Executive brief
Docling, a tool used to prepare documents for AI applications, is vulnerable to a denial-of-service attack. By providing a specially crafted archive file containing a malicious XML document, an attacker can cause the system to consume excessive resources. This can lead to the application becoming unresponsive or crashing, disrupting document processing operations.
Technical details
Docling's METS GBS backend is vulnerable to an XML Entity Expansion (XXE) attack, specifically an 'XML Bomb'. The vulnerability exists because the backend uses the 'etree.fromstring()' function to parse XML files extracted from .tar.gz archives without disabling entity resolution. An attacker can exploit this by submitting a crafted archive containing an XML file with deeply nested entity definitions. When parsed, these entities expand exponentially, leading to extreme CPU and memory consumption. This results in a denial-of-service (DoS) on the host system. The vulnerability affects versions up to and including 2.61.0; as of the advisory date, no patched version is specified.
Affected products
- docling-project docling <= 2.61.0
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory: GitHub Advisory published