GHSA-cgc7-9qp3-86m3

Suggest an improvement
Source
https://github.com/advisories/GHSA-cgc7-9qp3-86m3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cgc7-9qp3-86m3/GHSA-cgc7-9qp3-86m3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cgc7-9qp3-86m3
Aliases
Published
2026-10-07T20:41:02Z
Modified
2026-10-07T20:45:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion
Details

Summary

The HTML, JATS, ODS (OpenDocument spreadsheet) and BoxNote backends accept table rowspan / colspan values without an upper bound. A few bytes of input, such as <td rowspan="100000000">, make docling run loops proportional to the declared span and allocate a table grid of the declared size. The result is CPU and memory exhaustion.

Details

  • docling/backend/html_backend.py (_get_cell_spans) parses span attributes with no upper limit. The cell-filling loop then iterates row_span × col_span times.
  • docling/backend/jats_backend.py and docling/backend/boxnote_backend.py fill their tables the same way.
  • The OpenDocument spreadsheet path scans the declared span range.
  • Export (for example export_to_markdown()) materialises the full grid through TableData.grid in docling-core.

document_timeout does not bound this. It is checked between pipeline stages, and these backends convert the whole document in a single call. max_file_size and max_num_pages do not help because the payload is tiny.

Measured on 2.130.0: a 54-byte HTML file with rowspan="1e8" takes about 4.4 s of CPU, and the time grows linearly with the value. A 52-byte file with colspan="3000000" takes about 23 s and reaches 4.5 GB peak memory during Markdown export.

Impact

Denial of service of the converting process from a very small input document. Confidentiality and integrity are not affected.

Proof of concept

<table><tr><td colspan="3000000">x</td></tr></table>
from docling.document_converter import DocumentConverter
DocumentConverter().convert("span.html").document.export_to_markdown()

Patches

Fixed in docling 2.131.0 by #4414. Table spans are clamped to the HTML limits (colspan 1000, rowspan 65534) and to the actual size of the table in the HTML, JATS, BoxNote and OpenDocument spreadsheet backends, so conversion time and memory grow with the real table only.

Workarounds

Upgrade to 2.131.0. For older versions:

Run conversions of untrusted documents in a separate process with memory and CPU-time limits, or restrict allowed_formats to formats that are not affected.

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-789"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:41:02Z",
    "nvd_published_at": "2026-10-05T22:16:57Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / docling

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.131.0

Affected versions

2.*
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.3.1
2.4.0
2.4.1
2.4.2
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.23.1
2.24.0
2.25.0
2.25.1
2.25.2
2.26.0
2.27.0
2.28.0
2.28.1
2.28.2
2.28.3
2.28.4
2.29.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.36.1
2.37.0
2.38.0
2.38.1
2.39.0
2.40.0
2.41.0
2.42.0
2.42.1
2.42.2
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.47.1
2.48.0
2.49.0
2.50.0
2.51.0
2.52.0
2.53.0
2.54.0
2.55.0
2.55.1
2.56.0
2.56.1
2.57.0
2.58.0
2.59.0
2.60.0
2.60.1
2.61.0
2.61.1
2.61.2
2.62.0
2.63.0
2.64.0
2.64.1
2.65.0
2.66.0
2.67.0
2.68.0
2.69.0
2.69.1
2.70.0
2.71.0
2.72.0
2.73.0
2.73.1
2.74.0
2.75.0
2.76.0
2.77.0
2.78.0
2.79.0
2.80.0
2.81.0
2.82.0
2.83.0
2.84.0
2.85.0
2.86.0
2.87.0
2.88.0
2.89.0
2.90.0
2.91.0
2.92.0
2.93.0
2.94.0
2.95.0
2.96.0
2.96.1
2.97.0
2.98.0
2.99.0
2.100.0
2.101.0
2.102.0
2.102.1
2.102.2
2.103.0
2.104.0
2.105.0
2.106.0
2.107.0
2.108.0
2.109.0
2.110.0
2.111.0
2.112.0
2.113.0
2.114.0
2.115.0
2.116.0
2.117.0
2.118.0
2.118.1
2.119.0
2.120.1
2.120.2
2.120.3
2.121.0
2.122.0
2.123.0
2.123.1
2.124.0
2.125.0
2.126.0
2.127.0
2.128.0
2.129.0
2.130.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cgc7-9qp3-86m3/GHSA-cgc7-9qp3-86m3.json"

PyPI / docling-slim

Package

Name
docling-slim
View open source insights on deps.dev
Purl
pkg:pypi/docling-slim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.92.0
Fixed
2.131.0

Affected versions

2.*
2.92.0
2.93.0
2.94.0
2.95.0
2.96.0
2.96.1
2.97.0
2.98.0
2.99.0
2.100.0
2.101.0
2.102.0
2.102.1
2.102.2
2.103.0
2.104.0
2.105.0
2.106.0
2.107.0
2.108.0
2.109.0
2.110.0
2.111.0
2.112.0
2.113.0
2.114.0
2.115.0
2.116.0
2.117.0
2.118.0
2.118.1
2.119.0
2.120.1
2.120.2
2.120.3
2.121.0
2.122.0
2.123.0
2.123.1
2.124.0
2.125.0
2.126.0
2.127.0
2.128.0
2.129.0
2.130.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cgc7-9qp3-86m3/GHSA-cgc7-9qp3-86m3.json"