CVE-2026-105749: Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/htmlbackend.py, docling/backend/jatsbackend.py, and docling/backend/boxnotebackend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the documenttimeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Doclingto a version that resolves this vulnerability.Fixed in 2.131.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using Docling versions from 2.0.0 until the fix in 2.131.0 are affected when they process HTML, JATS, OpenDocument spreadsheet, or BoxNote documents through the corresponding backends.
What must an attacker provide to trigger the resource exhaustion?
An attacker needs to cause Docling to process a document containing table rowspan or colspan attributes with extremely large declared values. Even a very small document can drive sustained CPU use or multi-gigabyte memory allocation.
Does setting document_timeout prevent this issue?
No. The document_timeout setting does not interrupt the single backend conversion call responsible for the excessive work.
Are there operations that can worsen the memory impact?
Yes. Exporting through the TableData.grid property can materialize the oversized table grid and further increase memory consumption.