{"data":{"id":"96ff7aa8-34f2-45cf-a715-21d57db0dbc1","title":"GHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing","summary":"The JSONReader in run-llama/llama_index version 0.12.28 is vulnerable to a stack overflow caused by uncontrolled recursive JSON parsing. An attacker can submit deeply nested JSON structures to trigger a RecursionError, crashing the application and causing a Denial of Service.","solution":"The issue is resolved in version 0.12.38.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-3wxx-q3gv-pvvv","publishedAt":"2025-07-07T12:30:23.000Z","cveId":"CVE-2025-5472","cweIds":["CWE-674"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["llama-index-core@< 0.12.38 (fixed: 0.12.38)"],"affectedPackageNames":["llama-index-core"],"affectedPackageRefs":["pypi:llama-index-core"],"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["LlamaIndex","JSONReader"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00388,"epssCheckedAt":"2026-10-10T04:57:14.461Z","kevDateAdded":null,"advisoryAliases":["GHSA-3wxx-q3gv-pvvv"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-07-07T12:30:23.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}