Vulnerability PYSEC-2026-4195

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 days ago
October 05, 2026 at 10:16 PM UTC
No summary available
2.0.0 - 2.130.0
2.0.0 - 2.130.0

Details

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.

Impacted packages

Timeline

Published
2 days ago
October 05, 2026 at 10:16 PM UTC
Fixed (2.131.0)
9 days ago
September 29, 2026 at 08:00 AM UTC
Last Modified
2 hours ago
October 08, 2026 at 10:00 AM UTC