MediumVulnerability
GHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
- Identifiers
- CVE-2025-5472GHSA-3wxx-q3gv-pvvv
- Published
- Record updated
- Affected
- llama-index-core < 0.12.38
- Fixed in
- 0.12.38
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The JSONReader in run-llama/llama_index version 0.12.28 is vulnerable to a stack overflow caused by uncontrolled recursive JSON parsing. An attacker can submit deeply nested JSON structures to trigger a RecursionError, crashing the application and causing a Denial of Service.
Mitigation
The issue is resolved in version 0.12.38.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database