Skip to content
MediumVulnerability

GHSA-3hjh-jh2h-vrg6: Denial of service in langchain-community

Published
Record updated
View JSON
Affected
  • langchain-community < 0.2.5
  • langchain >= 0, < 0.2.5
Fixed in
0.2.5
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The `SitemapLoader` Document Loader in the `langchain-community` package, in versions below 0.2.5, has a denial of service flaw. The `parse_sitemap` method does not stop infinite recursion when a sitemap URL points back to the current sitemap, so it crashes the Python process by exceeding the maximum recursion depth. An attacker can occupy server socket/port resources, which impacts the availability of services that use this functionality.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.