Skip to content

[GHSA-9f4q-q82q-4359] Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks - #9914

Open
chrikrah wants to merge 1 commit into
github:chrikrah/advisory-improvement-9914from
chrikrah:chrikrah-GHSA-9f4q-q82q-4359
Open

chrikrah wants to merge 1 commit into
github:chrikrah/advisory-improvement-9914from
chrikrah:chrikrah-GHSA-9f4q-q82q-4359

Conversation

@chrikrah

@chrikrah chrikrah commented Oct 1, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • References

Comments
The record says introduced: 0, last_affected: 2.61.0. The METS GBS backend first shipped in 2.45.0, and _validate_mets_xml called etree.fromstring(xml_string) with no parser until docling-project/docling#3336, first released in 2.91.0. This change moves both bounds to >= 2.45.0, < 2.91.0 and adds the fix PR, commit and release.

A .tar.gz with one METS file that holds five nested entities, loaded by MetsGbsDocumentBackend from a worktree at each tag:

$ PYTHONPATH=wt-v2.90.0 python probe_mets.py mets_bomb.tar.gz
root_mets set, expanded_A=100000
$ PYTHONPATH=wt-v2.91.0 python probe_mets.py mets_bomb.tar.gz
root_mets set, expanded_A=0
$ git log --diff-filter=A --format=%h -- docling/backend/mets_gbs_backend.py
31087f3f
$ git tag --contains 31087f3f --sort=v:refname | head -1
v2.45.0
$ git show v2.45.0:docling/backend/mets_gbs_backend.py | grep -n "fromstring(xml_string"
286:        root: etree._Element = etree.fromstring(xml_string)
$ git show v2.90.0:docling/backend/mets_gbs_backend.py | grep -n "fromstring(xml_string"
286:        root: etree._Element = etree.fromstring(xml_string)
$ git tag --contains c1dbac22 --sort=v:refname | head -1
v2.91.0

The JATS fix, docling-project/docling#3009, did not touch this backend, so GHSA-cr42-rg2m-mq4q gets 2.74.0 in a separate PR.

If you would rather keep last_affected, the value is 2.90.0: 2.90.1 was tagged but never published to PyPI.

@github-actions
github-actions Bot changed the base branch from main to chrikrah/advisory-improvement-9914 October 1, 2026 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant