Allocation of Resources Without Limits or Throttling Affecting docling package, versions [,2.74.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DOCLING-16757962
  • published19 May 2026
  • disclosed11 May 2026
  • creditUnknown

Introduced: 11 May 2026

NewCVE-2026-31247  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade docling to version 2.74.0 or higher.

Overview

docling is a SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the etree.parse function. An attacker can cause excessive resource consumption and disrupt service availability by submitting a crafted XML file containing a nested entity expansion payload.

CVSS Base Scores

version 4.0
version 3.1