Docling, Unbounded Table Span Denial of Service, CVE-2026-105749 (Medium) -DC-Oct2026-2861

Listen to this Post

The CVE-2026-105749 vulnerability resides in multiple document parsing backends of Docling, specifically affecting the HTML, JATS, BoxNote, and OpenDocument spreadsheet (ODS) handlers. When processing input files, these backends parse table cell span attributes such as `rowspan` and `colspan` directly from the source markup without implementing any upper bounds or validation checks. An attacker can craft a minuscule input document containing extremely large numeric values inside these attributes, such as `rowspan=”100000000″` or colspan="3000000", using only dozens of bytes. Upon ingestion, the underlying parser routines—specifically `_get_cell_spans` in `html_backend.py` and equivalent logic in the JATS, BoxNote, and ODS backends—initialize cell-filling loops whose iterations scale proportionally to the product of the declared row and column spans (row_span × col_span). Furthermore, when the document is exported (for instance, via export_to_markdown()), the framework materializes the full grid in memory through `TableData.grid` in docling-core. Because these format backends process the entire document in a single monolithic call, built-in safeguards like `document_timeout` fail to intercept the operation since timeouts are only evaluated between distinct pipeline stages. Similarly, configuration limits like `max_file_size` and `max_num_pages` provide no defense because the malicious payload itself is extremely small in physical file size. Consequently, processing a file containing these inflated span declarations forces the application to allocate massive multi-gigabyte table grids and consume continuous CPU resources, leading directly to severe resource exhaustion, memory allocation failures, and a complete Denial of Service (DoS) of the conversion pipeline.

DailyCVE Form:

Platform: Docling
Version: 2.130.0
Vulnerability: Unbounded table span
Severity: Medium
date: October 2026

Prediction: Patched in 2.131.0

What Undercode Say:

Analytics of the vulnerability indicate that attackers can leverage tiny payloads to trigger catastrophic resource consumption without requiring authentication or user interaction beyond processing the document. Below are diagnostic commands and version checks related to the analysis:

pip show docling
python3 -c "from docling.document_converter import DocumentConverter; DocumentConverter().convert('span.html')"

Exploit: (Educational Purposes!)

Proof of concept HTML payload file (`span.html`):


<table><tr><td colspan="3000000">x</td></tr></table>

Python exploitation script triggering memory and CPU exhaustion:

from docling.document_converter import DocumentConverter
DocumentConverter().convert("span.html").document.export_to_markdown()

Protection:

Upgrade Docling to version 2.131.0 or later, which introduces strict clamping for table spans to standard HTML limits (colspan max 1000, `rowspan` max 65534) and restricts them to actual table dimensions.
For older, unpatched versions, execute document conversion tasks of untrusted inputs within isolated worker processes enforced by strict memory and CPU-time limits.
Restrict `allowed_formats` in conversion pipelines to formats that do not accept unbounded table spans if untrusted files must be processed.

Impact:

Complete Denial of Service (DoS) of the document conversion pipeline due to CPU and memory exhaustion caused by minuscule input files.
Application crashes resulting from out-of-memory (OOM) errors when large grids are materialized via TableData.grid.
Confidentiality and integrity remain entirely unaffected, as no arbitrary code execution, data exfiltration, or unauthorized data modification occurs.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top