HighVulnerability
GHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReader
- Identifiers
- CVE-2025-5302GHSA-7753-xrfw-ch36
- Published
- Record updated
- Affected
- llama-index-core < 0.12.38
- Fixed in
- 0.12.38
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
A denial of service flaw exists in the JSONReader component of the run-llama/llama_index repository, in version v0.12.37. Parsing deeply nested JSON files triggers uncontrolled recursion, which can push Python past its maximum recursion depth limit, causing high resource consumption and potential crashes of the Python process.
Mitigation
The issue is resolved in version 0.12.38.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database
- MediumGHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsingSame vendor · GitHub Advisory Database