CVE-2026-108749
docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.
| CWE | CWE-306 |
| Vendor | docling-project |
| Product | docling-serve |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for docling-project docling-serve
Be the first to know when new low vulnerabilities affecting docling-project docling-serve are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
docling-project / docling-serve
1.14.0 โค 1.36.0
References
hackmd.io: https://hackmd.io/@haind03/docling-serve-memory-endpoints-api-key-bypass github.com: https://github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/app.py#L1631-L1687 github.com: https://github.com/docling-project/docling-serve/blob/07b1d3d3b515afd9196148e0353d54ea38de2a37/docling_serve/auth.py#L49-L55 github.com: https://github.com/docling-project/docling-serve vulncheck.com: https://www.vulncheck.com/advisories/docling-serve-1.14.0-through-1.36.0-missing-authentication-via-memory-management-endpoints
Credits
HaiND from the Post and Telecommunication Institute of Technology