HighVulnerability
GHSA-7c85-87cp-mr6g: LlamaIndex Vulnerable to Denial of Service (DoS)
- Identifiers
- CVE-2025-1752GHSA-7c85-87cp-mr6g
- Published
- Record updated
- Affected
- llama-index >= 0.12.15, < 0.12.21
- Fixed in
- 0.12.21
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
A Denial of Service vulnerability affects the KnowledgeBaseWebReader class in the run-llama/llama_index project, reported against version ~ latest(v0.12.15). The flaw stems from the max_depth parameter not being properly enforced in the get_article_urls function. An attacker can exhaust Python's recursion limit through repeated function calls, consuming resources and crashing the Python process.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-indexPyPILLM dependency since 2023-02-16 · 12 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database