Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20209 | LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing |
Github GHSA |
GHSA-3wxx-q3gv-pvvv | LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
| CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llamaindex
Llamaindex llamaindex |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 07 Jul 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Jul 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing applications. The root cause is the unsafe recursive traversal design and lack of depth validation, which makes the JSONReader susceptible to stack overflow when processing deeply nested JSON. This impacts the availability of services, making them unreliable and disrupting workflows. The issue is resolved in version 0.12.38. | |
| Title | Denial of Service via Uncontrolled Recursive JSON Parsing in JSONReader in run-llama/llama_index | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-07-07T11:23:35.709Z
Reserved: 2025-06-02T14:07:59.604Z
Link: CVE-2025-5472
Updated: 2025-07-07T11:23:31.772Z
Status : Analyzed
Published: 2025-07-07T10:15:28.873
Modified: 2025-07-30T20:03:35.977
Link: CVE-2025-5472
OpenCVE Enrichment
No data.
EUVD
Github GHSA