CVE-2026-105749: Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion

Published Oct 5, 2026
·
Updated

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/htmlbackend.py, docling/backend/jatsbackend.py, and docling/backend/boxnotebackend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the documenttimeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.

Affected Software

1 affected component
pypi/docling>=2.0.0<2.131.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Docling to a version that resolves this vulnerability.

    Fixed in 2.131.0

Event History

Oct 5, 2026
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using Docling versions from 2.0.0 until the fix in 2.131.0 are affected when they process HTML, JATS, OpenDocument spreadsheet, or BoxNote documents through the corresponding backends.

2

What must an attacker provide to trigger the resource exhaustion?

An attacker needs to cause Docling to process a document containing table rowspan or colspan attributes with extremely large declared values. Even a very small document can drive sustained CPU use or multi-gigabyte memory allocation.

3

Does setting document_timeout prevent this issue?

No. The document_timeout setting does not interrupt the single backend conversion call responsible for the excessive work.

4

Are there operations that can worsen the memory impact?

Yes. Exporting through the TableData.grid property can materialize the oversized table grid and further increase memory consumption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203