{"id":"CVE-2026-105749","summary":"Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.","aliases":["GHSA-cgc7-9qp3-86m3"],"modified":"2026-10-08T02:30:50.011059138Z","published":"2026-10-05T21:36:53.431Z","database_specific":{"cwe_ids":["CWE-400","CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105749.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105749.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4414"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docling-project/docling","events":[{"introduced":"a29c2560419bf4dd32bc87011c77516d0af5f522"},{"introduced":"80f81b2799112d66a59b4a292cad3a86d41d06ad"},{"fixed":"cb14c87372f3379de9ac19fa46aacf6abc762119"},{"fixed":"cb14c87372f3379de9ac19fa46aacf6abc762119"},{"fixed":"c5b4429cc6500a344c13edeb22e67610c2159b09"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.131.0"},{"introduced":"2.92.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.130.0","v2.129.0","v2.128.0","v2.127.0","v2.126.0","v2.125.0","v2.124.0","v2.123.1","v2.123.0","v2.122.0","v2.121.0","v2.120.3","v2.120.2","v2.120.1","v2.120.0","v2.119.0","v2.118.1","v2.118.0","v2.117.0","v2.116.0","v2.115.0","v2.114.0","v2.113.0","v2.112.0","v2.111.0","v2.110.0","v2.109.0","v2.108.0","v2.107.0","v2.106.0","v2.105.0","v2.104.0","v2.103.0","v2.102.2","v2.102.1","v2.102.0","v2.101.0","v2.100.0","v2.99.0","v2.98.0","v2.97.0","v2.96.1","v2.96.0","v2.95.0","v2.94.0","v2.93.0","v2.92.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105749.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}