
CVE-2026-31248 Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using e… https://www.cve.org/CVERecord?id=CVE-2026-31248
Post summary
The post announces the discovery of CVE‑2026‑31248, a documented XML Entity Expansion flaw in Docling’s METS GBS backend (v2.61.0) that parses XML files from .tar.gz archives.
