The METS-GBS backend's XML parsing and the input document format detection lacked security controls, enabling:
An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes.
Fixed in version 2.91.0. The fix implements:
resolve_entities=False, load_dtd=False, and no_network=True_detect_mets_gbs() method: maximum file size (10 MB per file), maximum member count (1000 members), and exception handling to gracefully fail when limits are exceededAvoid processing METS-GBS archives from untrusted sources. If necessary, pre-validate archives in an isolated environment with resource limits.
{
"cwe_ids": [
"CWE-409",
"CWE-611",
"CWE-776"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-03T21:13:32Z",
"nvd_published_at": "2026-06-26T16:16:30Z",
"severity": "MODERATE"
}