Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44018

Опубликовано: 26 июн. 2026
Источник: nvd
CVSS3: 5.5
CVSS3: 7.1
EPSS Низкий

Описание

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*
Версия от 2.45.0 (включая) до 2.91.0 (исключая)

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 5.5
redhat
около 1 месяца назад

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

CVSS3: 5.5
github
2 месяца назад

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-409