{"id":"CVE-2026-105747","summary":"Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.","aliases":["GHSA-3cr3-8m4c-fpxw"],"modified":"2026-10-06T10:45:46.891172613Z","published":"2026-10-05T21:32:34.438Z","database_specific":{"cwe_ids":["CWE-409","CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105747.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105747.json"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/ebae65cd71c37c88b36185b406a449b92d8f7ffa"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4412"},{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-3cr3-8m4c-fpxw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105747"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docling-project/docling","events":[{"introduced":"c3a7d1d999508ac46700291caab5ffa083dcdc86"},{"fixed":"cb14c87372f3379de9ac19fa46aacf6abc762119"}],"database_specific":{"extracted_events":[{"introduced":"2.45.0"},{"fixed":"2.131.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.130.0","v2.129.0","v2.128.0","v2.127.0","v2.126.0","v2.125.0","v2.124.0","v2.123.1","v2.123.0","v2.122.0","v2.121.0","v2.120.3","v2.120.2","v2.120.1","v2.120.0","v2.119.0","v2.118.1","v2.118.0","v2.117.0","v2.116.0","v2.115.0","v2.114.0","v2.113.0","v2.112.0","v2.111.0","v2.110.0","v2.109.0","v2.108.0","v2.107.0","v2.106.0","v2.105.0","v2.104.0","v2.103.0","v2.102.2","v2.102.1","v2.102.0","v2.101.0","v2.100.0","v2.99.0","v2.98.0","v2.97.0","v2.96.1","v2.96.0","v2.95.0","v2.94.0","v2.93.0","v2.92.0","v2.90.1","v2.91.0","v2.90.0","v2.89.0","v2.88.0","v2.87.0","v2.86.0","v2.85.0","v2.84.0","v2.83.0","v2.82.0","v2.81.0","v2.80.0","v2.79.0","v2.78.0","v2.77.0","v2.76.0","v2.75.0","v2.74.0","v2.73.1","v2.73.0","v2.72.0","v2.71.0","v2.70.0","v2.69.1","v2.69.0","v2.68.0","v2.67.0","v2.66.0","v2.65.0","v2.64.1","v2.64.0","v2.63.0","v2.62.0","v2.61.2","v2.61.1","v2.61.0","v2.60.1","v2.60.0","v2.59.0","v2.58.0","v2.57.0","v2.56.1","v2.56.0","v2.55.1","v2.55.0","v2.54.0","v2.53.0","v2.52.0","v2.51.0","v2.50.0","v2.49.0","v2.48.0","v2.47.1","v2.47.0","v2.46.0","v2.45.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105747.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"}]}