CVE-2026-108749 | docling-project docling-serve up to 1.36.0 /v1/memory/stats require_auth DOCLING_SERVE_API_KEY missing authentication

SecurityVulns

A vulnerability identified as critical has been detected in docling-project docling-serve up to 1.36.0. This affects the function require_auth of the file /v1/memory/stats. Performing a manipulation of the argument DOCLING_SERVE_API_KEY results in missing authentication.

This vulnerability is cataloged as CVE-2026-108749. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More