Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44018

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 5.5

Описание

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

A flaw was found in Docling, a tool for document processing. The METS-GBS backend, responsible for parsing XML and detecting document formats, lacked sufficient security controls. This allowed an attacker to create specially crafted METS-GBS archives. When these archives were processed, they could lead to the exhaustion of system resources or cause the application to crash, resulting in a Denial of Service (DoS). Additionally, this vulnerability could also enable the disclosure of sensitive files.

Отчет

The vulnerability in Docling, rated Moderate, allows for sensitive file disclosure and denial of service within Red Hat OpenShift AI when processing untrusted METS-GBS archives. This is due to insufficient security controls in the XML parsing and document format detection, which an attacker could exploit using crafted archives to trigger XML External Entity (XXE) attacks or decompression bombs.

Меры по смягчению последствий

To mitigate this issue, avoid processing METS-GBS archives from untrusted or unverified sources. If processing such archives is unavoidable, ensure they are pre-validated within an isolated environment with strict resource limits to prevent resource exhaustion and unauthorized file access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2493607docling: Docling: Denial of Service via crafted document archives

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 месяца назад

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

CVSS3: 5.5
github
2 месяца назад

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

5.5 Medium

CVSS3