GHSA-9f4q-q82q-4359

Suggest an improvement
Source
https://github.com/advisories/GHSA-9f4q-q82q-4359
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-9f4q-q82q-4359/GHSA-9f4q-q82q-4359.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9f4q-q82q-4359
Aliases
  • CVE-2026-31248
Published
2026-05-11T18:31:44Z
Modified
2026-05-18T15:36:52.044839Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
Details

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested entity definitions (XML Bomb) and package it into a .tar.gz archive. When processed by Docling, the exponential expansion of entities during XML parsing leads to excessive resource consumption, resulting in a denial of service (DoS) condition on the system running the Docling parser.

Database specific
{
    "cwe_ids": [
        "CWE-776"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-18T15:21:03Z",
    "nvd_published_at": "2026-05-11T17:16:19Z",
    "severity": "HIGH"
}
References

Affected packages

PyPI / docling

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.61.0

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.3.1
0.4.0
1.*
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.10.0
1.11.0
1.12.0
1.12.1
1.12.2
1.13.0
1.13.1
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
1.18.0
1.19.0
1.19.1
1.20.0
2.*
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.3.1
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.23.1
2.24.0
2.25.0
2.25.1
2.25.2
2.26.0
2.27.0
2.28.0
2.28.1
2.28.2
2.28.3
2.28.4
2.29.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.36.1
2.37.0
2.38.0
2.38.1
2.39.0
2.40.0
2.41.0
2.42.0
2.42.1
2.42.2
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.47.1
2.48.0
2.49.0
2.50.0
2.51.0
2.52.0
2.53.0
2.54.0
2.55.0
2.55.1
2.56.0
2.56.1
2.57.0
2.58.0
2.59.0
2.60.0
2.60.1
2.61.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-9f4q-q82q-4359/GHSA-9f4q-q82q-4359.json"