CVE-2026-44018: Docling METS-GBS XML Parsing Vulnerability (v2.45-2.90)
Docling, a document processing library that integrates with AI systems, contains a vulnerability in how it handles METS-GBS (a specialized XML-based document archive format) files. Versions 2.45.0 through 2.90.x lack proper security checks when parsing these archives. An attacker could create a malicious METS-GBS file that, when opened by a user in an application using vulnerable Docling, could read files from the system, consume excessive memory or CPU, or crash the application. The vulnerability requires user interaction—the file must be opened—but doesn't require special privileges to trigger.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-409, CWE-611, CWE-776
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-26 / 2026-06-27
NVD description (verbatim)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from insufficient input validation in the METS-GBS backend's XML parser (CWE-611: Improper Restriction of XML External Entity Reference) and weak document format detection logic (CWE-409: Improper Handling of Highly Compressed Data, CWE-776: Improper Restriction of Recursive Entity References in DTDs). When Docling processes a specially crafted METS-GBS archive, the parser may resolve external entities, process maliciously nested structures, or fail to bound resource consumption. This can lead to information disclosure through local file reads, denial of service through resource exhaustion, or application crashes.
Business impact
For organizations using Docling in document processing pipelines—particularly those handling user-uploaded files or documents from external sources—this vulnerability creates both availability and confidentiality risks. An attacker with the ability to supply documents could disrupt service availability or, in multi-tenant or shared-system environments, potentially access configuration files or temporary data. The impact is bounded by file system permissions and the application's execution context, but in typical deployment scenarios, sensitive files within the application's read scope could be exposed.
Affected systems
Docling versions 2.45.0 through 2.90.x are affected. Version 2.91.0 and later contain the fix. Any application or service that embeds Docling and processes METS-GBS documents—especially those accepting user-supplied files—is at risk. Assess your inventory for Docling usage across document processing, data ingestion, and AI-powered analysis workflows.
Exploitability
Exploitation requires user interaction: a user must open or process a malicious METS-GBS file. No network attack vector or elevated privileges are needed. The attacker surface is limited to scenarios where documents can be supplied externally—file uploads, email attachments processed by automation, or shared document repositories. Docling is not a widely deployed end-user application, so risk is concentrated in organizations that have integrated it into their infrastructure.
Remediation
Upgrade Docling to version 2.91.0 or later. The fix hardens XML parsing by restricting external entity resolution and validates METS-GBS archive structure more strictly. For applications that cannot upgrade immediately, implement input validation to reject or sandbox untrusted METS-GBS files, and restrict Docling's file system access via OS-level controls (chroot, containers, least-privilege accounts).
Patch guidance
Docling 2.91.0 addresses the vulnerability. Coordinate the upgrade with your application release cycle, as Docling is typically a dependency rather than a standalone service. Verify compatibility with your current Docling integration before deploying to production. Check the vendor advisory for any breaking changes or migration notes. If your application vendor provides Docling as part of a bundled package, ensure they have released a patched version of their product.
Detection guidance
Monitor logs for unusual METS-GBS file processing patterns, such as exceptions during XML parsing, excessive memory consumption during document processing, or unexpected file access from Docling processes. Network-based detection is limited since this is a local file parsing issue. Endpoint detection should focus on anomalous behavior from applications using Docling when processing untrusted documents—e.g., unusual system calls, resource spikes, or failed file access attempts.
Why prioritize this
This vulnerability merits prompt but not emergency attention. The CVSS score of 5.5 (Medium) reflects the requirement for user interaction and limited attack surface. However, if your organization accepts user-supplied documents or integrates Docling into automated pipelines, prioritize patching to close the availability and confidentiality window. Organizations processing only internal, trusted documents face lower risk.
Risk score, explained
CVSS 5.5 reflects: (1) local attack vector—the file must be processed on the victim's system; (2) no privileges required; (3) user interaction needed; (4) high availability impact (resource exhaustion, crashes) but no confidentiality or integrity impact noted in the base vector. Note that the CWE mappings suggest information disclosure is possible (file reads), which may not be fully reflected in the base CVSS. Assess confidentiality risk in your context based on what files Docling can access.
Frequently asked questions
What is METS-GBS and why is it used?
METS-GBS (Metadata Encoding and Transmission Standard – German Book Server) is an XML-based format for encoding digitized document metadata and structure, commonly used in digital library and document preservation contexts. Docling supports it to handle archival and scanned document formats. It is not a widely used consumer format, so exposure is limited to organizations processing archival or library content.
Can this vulnerability be exploited remotely?
No. The vulnerability requires local file processing. An attacker cannot exploit it by sending a specially crafted file over the network; the file must be opened and processed by Docling on the target system, typically requiring user action or an automated workflow that processes untrusted files.
Does upgrading to 2.91.0 have any breaking changes?
The vendor advisory should be consulted for compatibility notes. Security-focused parser hardening typically does not break legitimate use cases, but verify in your test environment before production deployment.
If we only process internal, trusted documents, do we need to patch?
Risk is substantially lower if all documents originate from internal, trusted sources. However, patching remains recommended to eliminate the attack surface. If your workflow could ever process external documents—even occasionally—prioritize the upgrade.
This analysis is based on publicly available CVE and vendor information as of the publication date. Security vulnerabilities and patch availability may change; always verify current status with official vendor advisories and changelogs. Exploit code or proof-of-concept details are not provided to minimize risk of weaponization. Organizations should conduct their own risk assessment based on their specific deployment and data sensitivity. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-44020HIGHXXE Vulnerability in Docling USPTO Patent Parser
- CVE-2025-58175MEDIUMGeoServer SSRF Vulnerability in Proxy Configuration
- CVE-2026-12788MEDIUMXXE Vulnerability in zhilink ADP Platform 1.0.0 – Authentication Required
- CVE-2026-12993MEDIUMApicurio Registry XML Entity Expansion DoS
- CVE-2026-40991MEDIUMSpring REST Docs XXE Injection in Remote API Documentation
- CVE-2026-48981MEDIUMXXE Vulnerability in pam_usb Configuration Parsing
- CVE-2026-54233MEDIUMvLLM Audio Transcription Denial of Service (CVSS 6.5)
- CVE-2026-54470MEDIUMDell Unisphere for PowerMax XXE Vulnerability – Patch Guide & Risk Analysis