Skip to content
MediumVulnerability

GHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

Published
Record updated
View JSON
Affected
  • llama-index-core < 0.12.38
Fixed in
0.12.38
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

The JSONReader in run-llama/llama_index version 0.12.28 is vulnerable to a stack overflow caused by uncontrolled recursive JSON parsing. An attacker can submit deeply nested JSON structures to trigger a RecursionError, crashing the application and causing a Denial of Service.

Mitigation

The issue is resolved in version 0.12.38.