A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.
History

Mon, 25 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Run-llama
Run-llama llama Index
Vendors & Products Run-llama
Run-llama llama Index

Mon, 25 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Description A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.
Title Denial of Service (DOS) in JSONReader in run-llama/llama_index
Weaknesses CWE-674
References
Metrics cvssV3_0

{'score': 8.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-08-25T15:03:18.097Z

Updated: 2025-08-25T15:41:08.676Z

Reserved: 2025-05-28T10:16:07.938Z

Link: CVE-2025-5302

cve-icon Vulnrichment

Updated: 2025-08-25T15:41:03.489Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-25T15:15:42.243

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-5302

cve-icon Redhat

No data.