A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0987 | A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS). |
Github GHSA |
GHSA-q84m-rmw3-4382 | LangChain's XMLOutputParser vulnerable to XML Entity Expansion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain |
|
| CPEs | cpe:2.3:a:langchain:langchain:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langchain
Langchain langchain |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-15T15:56:19.154Z
Reserved: 2024-02-12T16:51:50.188Z
Link: CVE-2024-1455
Updated: 2024-08-01T18:40:21.288Z
Status : Analyzed
Published: 2024-03-26T14:15:08.450
Modified: 2025-07-30T20:06:23.577
Link: CVE-2024-1455
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:01:08Z
EUVD
Github GHSA