A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the max_depth parameter in the get_article_urls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.
History

Mon, 12 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 14:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Sat, 10 May 2025 13:30:00 +0000

Type Values Removed Values Added
Description A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the max_depth parameter in the get_article_urls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.
Title Denial of Service in run-llama/llama_index
Weaknesses CWE-400
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-05-10T13:21:30.866Z

Updated: 2025-05-12T17:47:23.693Z

Reserved: 2025-02-27T11:24:38.795Z

Link: CVE-2025-1752

cve-icon Vulnrichment

Updated: 2025-05-12T17:47:11.608Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-10T14:15:32.523

Modified: 2025-05-12T18:15:43.960

Link: CVE-2025-1752

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-10T13:21:30Z

Links: CVE-2025-1752 - Bugzilla