{"data":{"id":"d1ac1a12-03f3-4aa0-869d-94864d94a986","title":"GHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReader","summary":"A denial of service flaw exists in the JSONReader component of the run-llama/llama_index repository, in version v0.12.37. Parsing deeply nested JSON files triggers uncontrolled recursion, which can push Python past its maximum recursion depth limit, causing high resource consumption and potential crashes of the Python process.","solution":"The issue is resolved in version 0.12.38.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-7753-xrfw-ch36","publishedAt":"2025-08-26T00:31:13.000Z","cveId":"CVE-2025-5302","cweIds":["CWE-674"],"cvssScore":"8.6","cvssSeverity":"high","severity":"high","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["llama-index-core@< 0.12.38 (fixed: 0.12.38)"],"affectedPackageNames":["llama-index-core"],"affectedPackageRefs":["pypi:llama-index-core"],"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["LlamaIndex","JSONReader"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00285,"epssCheckedAt":"2026-10-10T04:57:13.550Z","kevDateAdded":null,"advisoryAliases":["GHSA-7753-xrfw-ch36"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-08-26T00:31:13.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null}}