CVE-2026-31247Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed by Docling, the exponential expansion of entities leads to excessive resource consumption, resulting in a denial of service (DoS) condition on the system running the Docling parser.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Technical Details · 2026-05-11: 205-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31247 XML Entity Expansion Denial of Service in Docling JATS XML Backen... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31247 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces the CVE-2026-31247, describing it as an XML entity expansion denial‑of‑service vulnerability with a link to vulnerability details, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000059
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31247 Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity… https://www.cve.org/CVERecord?id=CVE-2026-31247

    Post summary

    The text discloses a new XML Entity Expansion flaw in Docling’s JATS XML backend (CVE-2026-31247), citing affected version and parsing behavior, but lists no exploit, PoC, or mitigation details.

    00000175
    57.5K followersView on X

Explore more