CVE-2026-44018
docling-project docling
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
- CVSS
- 7.1
- EPSS
- 0.11% 1.65% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.27