Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed by Docling, the exponential expansion of entities leads to excessive resource consumption, resulting in a denial of service (DoS) condition on the system running the Docling parser.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-11 16:17
Updated : 2026-06-17 10:33
NVD link : CVE-2026-31247
Mitre link : CVE-2026-31247
CVE.ORG link : CVE-2026-31247
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
