« Volver al listado

CVE-2026-105747

Estado: AnalizadaMedia (4.3)—

Docling simplifica el procesamiento de documentos analizando formatos diversos y proporcionando integraciones con el ecosistema de IA generativa. Desde la 2.45.0 hasta la 2.131.0, la detección del formato METS-GBS en docling/datamodel/document.py y el backend en docling/backend/mets_gbs_backend.py llaman a tarfile.TarFile.getmembers() antes de aplicar el límite max_member_count, lo que hace que se asigne la lista completa de miembros del archivo antes de que el límite pueda detener el procesamiento.

Leer descripción completaMostrar menos

Por tanto, un pequeño archivo tar comprimido con gzip con un número muy elevado de miembros vacíos puede consumir memoria proporcional al número de miembros declarado, incluso durante la detección del formato antes de que se aplique la restricción allowed_formats. Este problema es una debilidad residual de la protección del número de miembros añadida para CVE-2026-44018. Este problema se ha corregido en la 2.131.0.

Traducción automática del texto original de NVD (en inglés).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con UI:R indica interacción del usuario (abrir documento). Archivo tar comprimido malicioso causa exhaustión de memoria durante lectura, negando servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-105747",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-105747",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-10-06T14:34:13.770203Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "docling-project",
          "product": "docling",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.45.0, < 2.131.0"
            }
          ]
        },
        {
          "vendor": "docling-project",
          "product": "docling-slim",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.45.0, < 2.131.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-10-05T22:16:57.633",
  "references": [
    {
      "url": "https://github.com/docling-project/docling/commit/ebae65cd71c37c88b36185b406a449b92d8f7ffa",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/pull/4412",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/releases/tag/v2.131.0",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/security/advisories/GHSA-3cr3-8m4c-fpxw",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-409"
        },
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0."
    }
  ],
  "lastModified": "2026-10-07T18:54:39.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C056F86-D184-4241-B795-2626129F2717",
              "versionEndExcluding": "2.131.0",
              "versionStartIncluding": "2.45.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}