VYPR
Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026

CVE-2026-44018

CVE-2026-44018

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
doclingPyPI
>= 2.45.0, < 2.91.02.91.0

Affected products

3
  • Docling Project/Doclingllm-fuzzy2 versions
    >=2.91.0+ 1 more
    • (no CPE)range: >=2.91.0
    • cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*range: >=2.45.0,<2.91.0
  • ghsa-coords
    Range: >= 2.45.0, < 2.91.0

Patches

Vulnerability mechanics

References

5

News mentions

1