Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026
CVE-2026-44018
CVE-2026-44018
Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
doclingPyPI | >= 2.45.0, < 2.91.0 | 2.91.0 |
Affected products
3>=2.91.0+ 1 more
- (no CPE)range: >=2.91.0
- cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*range: >=2.45.0,<2.91.0
Patches
Vulnerability mechanics
References
5- github.com/docling-project/docling/security/advisories/GHSA-r3xg-rg9j-67fvnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-r3xg-rg9j-67fvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44018ghsaADVISORY
- github.com/docling-project/docling/releases/tag/v2.91.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/docling/PYSEC-2026-2144.yamlghsaWEB
News mentions
1- Docling Project: Eight High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Jun 3, 2026