Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration. | |
| Title | docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:49.965Z
Reserved: 2026-10-11T01:53:24.755Z
Link: CVE-2026-108749
No data.
Status : Received
Published: 2026-10-11T13:17:19.670
Modified: 2026-10-11T13:17:19.670
Link: CVE-2026-108749
No data.
OpenCVE Enrichment
Updated: 2026-10-11T14:00:18Z
