Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-44018

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.1%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-44018
  • Docling » Docling » Version: 2.45.0
    cpe:2.3:a:docling:docling:2.45.0
  • Docling » Docling » Version: 2.46.0
    cpe:2.3:a:docling:docling:2.46.0
  • Docling » Docling » Version: 2.47.0
    cpe:2.3:a:docling:docling:2.47.0
  • Docling » Docling » Version: 2.47.1
    cpe:2.3:a:docling:docling:2.47.1
  • Docling » Docling » Version: 2.48.0
    cpe:2.3:a:docling:docling:2.48.0
  • Docling » Docling » Version: 2.49.0
    cpe:2.3:a:docling:docling:2.49.0
  • Docling » Docling » Version: 2.50.0
    cpe:2.3:a:docling:docling:2.50.0
  • Docling » Docling » Version: 2.51.0
    cpe:2.3:a:docling:docling:2.51.0
  • Docling » Docling » Version: 2.52.0
    cpe:2.3:a:docling:docling:2.52.0
  • Docling » Docling » Version: 2.53.0
    cpe:2.3:a:docling:docling:2.53.0
  • Docling » Docling » Version: 2.54.0
    cpe:2.3:a:docling:docling:2.54.0
  • Docling » Docling » Version: 2.55.0
    cpe:2.3:a:docling:docling:2.55.0
  • Docling » Docling » Version: 2.55.1
    cpe:2.3:a:docling:docling:2.55.1
  • Docling » Docling » Version: 2.56.0
    cpe:2.3:a:docling:docling:2.56.0
  • Docling » Docling » Version: 2.56.1
    cpe:2.3:a:docling:docling:2.56.1
  • Docling » Docling » Version: 2.57.0
    cpe:2.3:a:docling:docling:2.57.0
  • Docling » Docling » Version: 2.58.0
    cpe:2.3:a:docling:docling:2.58.0
  • Docling » Docling » Version: 2.59.0
    cpe:2.3:a:docling:docling:2.59.0
  • Docling » Docling » Version: 2.60.0
    cpe:2.3:a:docling:docling:2.60.0
  • Docling » Docling » Version: 2.60.1
    cpe:2.3:a:docling:docling:2.60.1
  • Docling » Docling » Version: 2.61.0
    cpe:2.3:a:docling:docling:2.61.0
  • Docling » Docling » Version: 2.61.1
    cpe:2.3:a:docling:docling:2.61.1
  • Docling » Docling » Version: 2.61.2
    cpe:2.3:a:docling:docling:2.61.2
  • Docling » Docling » Version: 2.62.0
    cpe:2.3:a:docling:docling:2.62.0
  • Docling » Docling » Version: 2.63.0
    cpe:2.3:a:docling:docling:2.63.0
  • Docling » Docling » Version: 2.64.0
    cpe:2.3:a:docling:docling:2.64.0
  • Docling » Docling » Version: 2.64.1
    cpe:2.3:a:docling:docling:2.64.1
  • Docling » Docling » Version: 2.65.0
    cpe:2.3:a:docling:docling:2.65.0
  • Docling » Docling » Version: 2.66.0
    cpe:2.3:a:docling:docling:2.66.0
  • Docling » Docling » Version: 2.67.0
    cpe:2.3:a:docling:docling:2.67.0
  • Docling » Docling » Version: 2.68.0
    cpe:2.3:a:docling:docling:2.68.0
  • Docling » Docling » Version: 2.69.0
    cpe:2.3:a:docling:docling:2.69.0
  • Docling » Docling » Version: 2.69.1
    cpe:2.3:a:docling:docling:2.69.1
  • Docling » Docling » Version: 2.70.0
    cpe:2.3:a:docling:docling:2.70.0
  • Docling » Docling » Version: 2.71.0
    cpe:2.3:a:docling:docling:2.71.0
  • Docling » Docling » Version: 2.72.0
    cpe:2.3:a:docling:docling:2.72.0
  • Docling » Docling » Version: 2.73.0
    cpe:2.3:a:docling:docling:2.73.0
  • Docling » Docling » Version: 2.73.1
    cpe:2.3:a:docling:docling:2.73.1
  • Docling » Docling » Version: 2.74.0
    cpe:2.3:a:docling:docling:2.74.0
  • Docling » Docling » Version: 2.75.0
    cpe:2.3:a:docling:docling:2.75.0
  • Docling » Docling » Version: 2.76.0
    cpe:2.3:a:docling:docling:2.76.0
  • Docling » Docling » Version: 2.77.0
    cpe:2.3:a:docling:docling:2.77.0
  • Docling » Docling » Version: 2.78.0
    cpe:2.3:a:docling:docling:2.78.0
  • Docling » Docling » Version: 2.79.0
    cpe:2.3:a:docling:docling:2.79.0
  • Docling » Docling » Version: 2.80.0
    cpe:2.3:a:docling:docling:2.80.0
  • Docling » Docling » Version: 2.81.0
    cpe:2.3:a:docling:docling:2.81.0
  • Docling » Docling » Version: 2.82.0
    cpe:2.3:a:docling:docling:2.82.0
  • Docling » Docling » Version: 2.83.0
    cpe:2.3:a:docling:docling:2.83.0
  • Docling » Docling » Version: 2.84.0
    cpe:2.3:a:docling:docling:2.84.0
  • Docling » Docling » Version: 2.85.0
    cpe:2.3:a:docling:docling:2.85.0
  • Docling » Docling » Version: 2.86.0
    cpe:2.3:a:docling:docling:2.86.0
  • Docling » Docling » Version: 2.87.0
    cpe:2.3:a:docling:docling:2.87.0
  • Docling » Docling » Version: 2.88.0
    cpe:2.3:a:docling:docling:2.88.0
  • Docling » Docling » Version: 2.89.0
    cpe:2.3:a:docling:docling:2.89.0
  • Docling » Docling » Version: 2.90.0
    cpe:2.3:a:docling:docling:2.90.0
  • Docling » Docling » Version: 2.90.1
    cpe:2.3:a:docling:docling:2.90.1


Contact Us

Shodan ® - All rights reserved