Disclosure summary
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.
Source-reported weakness categories
CWE-409, CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-105747
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-3cr3-8m4c-fpxw
Open original source · Updated Oct 06, 2026
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | docling | >= 2.45.0, < 2.131.0 | 2.131.0 |
| pip | docling-slim | >= 2.92.0, < 2.131.0 | 2.131.0 |
Original records & references
PUBLISHED 2026-10-05T18:16:57-04:00
MODIFIED 2026-10-06T11:17:14-04:00
INGESTED 2026-10-06T11:45:40-04:00