A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.
Metrics
Affected Vendors & Products
References
History
Mon, 25 Aug 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Run-llama
Run-llama llama Index |
|
Vendors & Products |
Run-llama
Run-llama llama Index |
Mon, 25 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 25 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38. | |
Title | Denial of Service (DOS) in JSONReader in run-llama/llama_index | |
Weaknesses | CWE-674 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-08-25T15:03:18.097Z
Updated: 2025-08-25T15:41:08.676Z
Reserved: 2025-05-28T10:16:07.938Z
Link: CVE-2025-5302

Updated: 2025-08-25T15:41:03.489Z

Status : Awaiting Analysis
Published: 2025-08-25T15:15:42.243
Modified: 2025-08-25T20:24:45.327
Link: CVE-2025-5302

No data.