CVE-2026-44018: Docling
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
Affected products
- Docling Docling: from 2.45.0, before 2.91.0 (fixed in 2.91.0)
Published 2026-06-26. Last modified 2026-06-27.