PatchSiren cyber security CVE debrief
CVE-2026-105747 docling-project CVE debrief
When processing gzip-compressed tar archives in METS-GBS format, docling allocates memory to store all archive members before enforcing the member count limit. This can lead to memory exhaustion if the archive has a large number of members. The issue was introduced in version 2.45.0 and fixed in version 2.131.0. A small archive with a very large number of empty members makes docling allocate memory in proportion to the member count, and the limit has no effect. Format detection runs for any application/gzip input before allowed_formats is applied, so the allocation happens even when METS-GBS is not an allowed format.
- Vendor
- docling-project
- Product
- docling
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for docling-based systems, especially those handling METS-GBS archives, should assess exposure and apply necessary patches or upgrades. They should prioritize verifying exposure in their docling-based systems and review compensating controls for exposed systems.
Why it matters
The vulnerability in docling allows for memory exhaustion when processing METS-GBS archives with a large number of members, potentially leading to denial of service. Defenders should verify exposure and prioritize patching or upgrading to a fixed version.
- Memory exhaustion during METS-GBS archive processing
- Potential denial of service due to excessive memory allocation
- Need for verification of exposure in docling-based systems
- Prioritization of patching or upgrading to a fixed version
Technical summary
The vulnerability occurs because docling/datamodel/document.py and docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers(), which builds the full member list in memory before checking the max_member_count limit. This can lead to memory exhaustion when processing archives with a large number of members. The eager enumeration it relies on has been there since METS-GBS detection was added in 2.45.0. Measured on Python 3.12: an archive of 1,000,000 empty members compresses to about 6.2 MB and makes getmembers() hold about 408 MB (about 66 times the input size).
Defensive priority
Defenders should prioritize verifying exposure in their docling-based systems, especially those handling METS-GBS archives, and apply the patch or upgrade to a fixed version.
Recommended defensive actions
- Verify exposure in docling-based systems handling METS-GBS archives
- Apply the patch or upgrade to a fixed version (2.131.0 or later)
- Review and adjust the max_member_count limit as necessary
- Monitor systems for potential memory exhaustion issues
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The issue arises from `docling/datamodel/document.py` and `docling/backend/mets_gbs_backend.py` iterating over `tar.getmembers()` and counting members inside the loop, leading to memory allocation proportional to the member count before the `max_member_count` limit is checked.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105747 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105747
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105747 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105747
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-3cr3-8m4c-fpxw.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/security/advisories/GHSA-3cr3-8m4c-fpxw
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/pull/4412
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/commit/ebae65cd71c37c88b36185b406a449b92d8f7ffa
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/releases/tag/v2.131.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.