HarborGuard / CVE
Back to search
HIGHCVE-2026-31247Published Modified CNA mitre

CVE-2026-31247: Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed by Docling, the exponential expansion of entities leads to excessive resource consumption, resulting in a denial of service (DoS) condition on the system running the Docling parser.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • n/a / n/a
    n/a
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-31247: Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2 | HarborGuard CVE