Low severity3.7NVD Advisory· Published Oct 11, 2026
CVE-2026-108749
CVE-2026-108749
Description
docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.
Affected products
1- Range: 1.14.0 - 1.36.0
Patches
Vulnerability mechanics
References
4- github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/app.pynvd
- github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/auth.pynvd
- hackmd.io/@haind03/docling-serve-memory-endpoints-api-key-bypassnvd
- www.vulncheck.com/advisories/docling-serve-1.14.0-through-1.36.0-missing-authentication-via-memory-management-endpointsnvd
News mentions
0No linked articles in our index yet.