CVE-2026-105749
Docling simplifica el procesamiento de documentos analizando formatos diversos y proporcionando integraciones con el ecosistema de IA generativa. Desde la 2.0.0 hasta la 2.131.0, los backends de HTML, JATS, hojas de cálculo OpenDocument y BoxNote, incluidos docling/backend/html_backend.py, docling/backend/jats_backend.py y docling/backend/boxnote_backend.py, aceptan los valores de los atributos rowspan y colspan sin un límite superior y ejecutan bucles o asignan una cuadrícula de tabla proporcional a la extensión declarada.
Leer descripción completaMostrar menos
Por tanto, un documento muy pequeño puede provocar un uso sostenido de la CPU o una asignación de memoria de varios gigabytes, y el ajuste document_timeout no interrumpe la llamada de conversión única del backend. La exportación mediante la propiedad TableData.grid puede materializar además la cuadrícula sobredimensionada. Este problema se ha corregido en la 2.131.0.
Traducción automática del texto original de NVD (en inglés).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Requiere interacción del usuario (UI:R) para abrir un documento malformado. El ataque causa consumo sostenido de CPU y asignación excesiva de memoria (DoS de aplicación), explotando bucles proporcionales a rowspan/colspan sin límite superior.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-400, CWE-789
Referencias
- https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09
- https://github.com/docling-project/docling/pull/4414
- https://github.com/docling-project/docling/releases/tag/v2.131.0
- https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3
- https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-105749",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-105749",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-10-08T02:28:41.797887Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "docling-project",
"product": "docling",
"versions": [
{
"status": "affected",
"version": ">= 2.0.0, < 2.131.0"
}
]
},
{
"vendor": "docling-project",
"product": "docling-slim",
"versions": [
{
"status": "affected",
"version": ">= 2.92.0, < 2.131.0"
}
]
}
]
}
],
"published": "2026-10-05T22:16:57.943",
"references": [
{
"url": "https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/pull/4414",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/releases/tag/v2.131.0",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
},
{
"lang": "en",
"value": "CWE-789"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0."
}
],
"lastModified": "2026-10-08T03:16:35.093",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06283271-0264-48A3-B1C2-DCA994108840",
"versionEndExcluding": "2.131.0",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}