Medium [CVE-2026-44018] Denial of Service via crafted document archives
This medium-severity Red Hat Linux advisory covers CVE-2026-44018 affecting Red Hat OpenShift AI (RHOAI).
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls.
An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
A flaw was found in Docling, a tool for document processing. This allowed an attacker to create specially crafted METS-GBS archives.
When these archives were processed, they could lead to the exhaustion of system resources or cause the application to crash, resulting in a Denial of Service (DoS). Additionally, this vulnerability could also enable the disclosure of sensitive files.
The vulnerability in Docling, rated Moderate, allows for sensitive file disclosure and denial of service within Red Hat OpenShift AI when processing untrusted METS-GBS archives. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
Weakness: CWE-611. Affected Red Hat products: Red Hat OpenShift AI (RHOAI).
Red Hat does not currently list a fixing RHSA for this CVE.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- To mitigate this issue, avoid processing METS-GBS archives from untrusted or unverified sources. If processing such archives is unavoidable, ensure they are pre-validated within an isolated environment with strict resource limits to prevent resource exhaustion and unauthorized file access.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.