Skip to main content
Loading…
    CVE-2026-31248 — Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disa — CVE Database · The Intelligence Room