{"id":"GHSA-cgc7-9qp3-86m3","summary":"Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion","details":"### Summary\n\nThe HTML, JATS, ODS (OpenDocument spreadsheet) and BoxNote backends accept table `rowspan` / `colspan` values without an upper bound. A few bytes of input, such as `\u003ctd rowspan=\"100000000\"\u003e`, make docling run loops proportional to the declared span and allocate a table grid of the declared size. The result is CPU and memory exhaustion.\n\n### Details\n\n- `docling/backend/html_backend.py` (`_get_cell_spans`) parses span attributes with no upper limit. The cell-filling loop then iterates `row_span × col_span` times.\n- `docling/backend/jats_backend.py` and `docling/backend/boxnote_backend.py` fill their tables the same way.\n- The OpenDocument spreadsheet path scans the declared span range.\n- Export (for example `export_to_markdown()`) materialises the full grid through `TableData.grid` in docling-core.\n\n`document_timeout` does not bound this. It is checked between pipeline stages, and these backends convert the whole document in a single call. `max_file_size` and `max_num_pages` do not help because the payload is tiny.\n\nMeasured on 2.130.0: a 54-byte HTML file with `rowspan=\"1e8\"` takes about 4.4 s of CPU, and the time grows linearly with the value. A 52-byte file with `colspan=\"3000000\"` takes about 23 s and reaches 4.5 GB peak memory during Markdown export.\n\n### Impact\n\nDenial of service of the converting process from a very small input document. Confidentiality and integrity are not affected.\n\n### Proof of concept\n\n```html\n\u003ctable\u003e\u003ctr\u003e\u003ctd colspan=\"3000000\"\u003ex\u003c/td\u003e\u003c/tr\u003e\u003c/table\u003e\n```\n\n```python\nfrom docling.document_converter import DocumentConverter\nDocumentConverter().convert(\"span.html\").document.export_to_markdown()\n```\n\n### Patches\n\nFixed in docling 2.131.0 by [#4414](https://github.com/docling-project/docling/pull/4414). Table spans are clamped to the HTML limits (colspan 1000, rowspan 65534) and to the actual size of the table in the HTML, JATS, BoxNote and OpenDocument spreadsheet backends, so conversion time and memory grow with the real table only.\n\n### Workarounds\n\nUpgrade to 2.131.0. For older versions:\n\nRun conversions of untrusted documents in a separate process with memory and CPU-time limits, or restrict `allowed_formats` to formats that are not affected.","aliases":["CVE-2026-105749"],"modified":"2026-10-07T20:45:05.352968360Z","published":"2026-10-07T20:41:02Z","database_specific":{"nvd_published_at":"2026-10-05T22:16:57Z","cwe_ids":["CWE-400","CWE-789"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-07T20:41:02Z"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749"},{"type":"WEB","url":"https://github.com/docling-project/docling/pull/4414"},{"type":"WEB","url":"https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"},{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.131.0"}]}],"versions":["2.0.0","2.1.0","2.10.0","2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.11.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.12.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.13.0","2.130.0","2.14.0","2.15.0","2.15.1","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.2.1","2.20.0","2.21.0","2.22.0","2.23.0","2.23.1","2.24.0","2.25.0","2.25.1","2.25.2","2.26.0","2.27.0","2.28.0","2.28.1","2.28.2","2.28.3","2.28.4","2.29.0","2.3.0","2.3.1","2.30.0","2.31.0","2.31.1","2.31.2","2.32.0","2.33.0","2.34.0","2.35.0","2.36.0","2.36.1","2.37.0","2.38.0","2.38.1","2.39.0","2.4.0","2.4.1","2.4.2","2.40.0","2.41.0","2.42.0","2.42.1","2.42.2","2.43.0","2.44.0","2.45.0","2.46.0","2.47.0","2.47.1","2.48.0","2.49.0","2.5.0","2.5.1","2.5.2","2.50.0","2.51.0","2.52.0","2.53.0","2.54.0","2.55.0","2.55.1","2.56.0","2.56.1","2.57.0","2.58.0","2.59.0","2.6.0","2.60.0","2.60.1","2.61.0","2.61.1","2.61.2","2.62.0","2.63.0","2.64.0","2.64.1","2.65.0","2.66.0","2.67.0","2.68.0","2.69.0","2.69.1","2.7.0","2.7.1","2.70.0","2.71.0","2.72.0","2.73.0","2.73.1","2.74.0","2.75.0","2.76.0","2.77.0","2.78.0","2.79.0","2.8.0","2.8.1","2.8.2","2.8.3","2.80.0","2.81.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.9.0","2.90.0","2.91.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cgc7-9qp3-86m3/GHSA-cgc7-9qp3-86m3.json"}},{"package":{"name":"docling-slim","ecosystem":"PyPI","purl":"pkg:pypi/docling-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.92.0"},{"fixed":"2.131.0"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.130.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cgc7-9qp3-86m3/GHSA-cgc7-9qp3-86m3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}