๐Ÿ” CVE Alert

CVE-2026-108749

LOW 3.7

docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.

CWE CWE-306
Vendor docling-project
Product docling-serve
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for docling-project docling-serve

Be the first to know when new low vulnerabilities affecting docling-project docling-serve are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

docling-project / docling-serve
1.14.0 โ‰ค 1.36.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/docling-serve-memory-endpoints-api-key-bypass github.com: https://github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/app.py#L1631-L1687 github.com: https://github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/auth.py#L49-L55 github.com: https://github.com/docling-project/docling-serve vulncheck.com: https://www.vulncheck.com/advisories/docling-serve-1.14.0-through-1.36.0-missing-authentication-via-memory-management-endpoints

Credits

HaiND from the Post and Telecommunication Institute of Technology