MediumVulnerability
GHSA-jvpf-xf32-2w4q: LlamaIndex Uncontrolled Resource Consumption vulnerability
- Identifiers
- CVE-2024-12910GHSA-jvpf-xf32-2w4q
- Published
- Record updated
- Affected
- llama-index < 0.12.9
- Fixed in
- 0.12.9
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
A flaw in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, lets an attacker control a URL variable so that it contains the root URL. This triggers infinite recursive calls to the get_article_urls method, which exhausts system resources and can crash the application, resulting in a Denial of Service.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-indexPyPILLM dependency since 2023-02-16 · 12 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database