Skip to content
HighVulnerability

GHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReader

Published
Record updated
View JSON
Affected
  • llama-index-core < 0.12.38
Fixed in
0.12.38
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

A denial of service flaw exists in the JSONReader component of the run-llama/llama_index repository, in version v0.12.37. Parsing deeply nested JSON files triggers uncontrolled recursion, which can push Python past its maximum recursion depth limit, causing high resource consumption and potential crashes of the Python process.

Mitigation

The issue is resolved in version 0.12.38.