{"id":"CVE-2026-44018","summary":"Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.","aliases":["GHSA-r3xg-rg9j-67fv","PYSEC-2026-2144"],"modified":"2026-08-12T03:51:38.358788217Z","published":"2026-06-26T15:40:42.422Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44018.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-409","CWE-611","CWE-776"]},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.91.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44018.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-r3xg-rg9j-67fv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44018"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docling-project/docling","events":[{"introduced":"c3a7d1d999508ac46700291caab5ffa083dcdc86"},{"fixed":"188b6a192c9463fcd2b666b0d68e300feec0ad2a"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*","extracted_events":[{"introduced":"2.45.0"},{"fixed":"2.91.0"}]}}],"versions":["v2.90.1","v2.90.0","v2.89.0","v2.88.0","v2.87.0","v2.86.0","v2.85.0","v2.84.0","v2.83.0","v2.82.0","v2.81.0","v2.80.0","v2.79.0","v2.78.0","v2.77.0","v2.76.0","v2.75.0","v2.74.0","v2.73.1","v2.73.0","v2.72.0","v2.71.0","v2.70.0","v2.69.1","v2.69.0","v2.68.0","v2.67.0","v2.66.0","v2.65.0","v2.64.1","v2.64.0","v2.63.0","v2.62.0","v2.61.2","v2.61.1","v2.61.0","v2.60.1","v2.60.0","v2.59.0","v2.58.0","v2.57.0","v2.56.1","v2.56.0","v2.55.1","v2.55.0","v2.54.0","v2.53.0","v2.52.0","v2.51.0","v2.50.0","v2.49.0","v2.48.0","v2.47.1","v2.47.0","v2.46.0","v2.45.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44018.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}