Knowledge base
CodexGuild Knowledge Base

LlamaIndex Vulnerable to Denial of Service (DoS)

as of May 10, 2025 · applies to llama-index >= 0.12.15, < 0.12.21 · canonical · codexguild.com/kb/ghsa-7c85-87cp-mr6g · exported 2026-10-11
Canonical as of May 10, 2025

LlamaIndex Vulnerable to Denial of Service (DoS)

High severity. Affects llama-index >= 0.12.15, < 0.12.21. Upgrade to 0.12.21 or later.

CVE-2025-1752 / GHSA-7c85-87cp-mr6g · severity: high · CVSS 7.5 · PyPI

Affected

  • llama-index >= 0.12.15, < 0.12.21 → fixed in 0.12.21

Details

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the max_depth parameter in the get_article_urls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.

Source: GHSA-7c85-87cp-mr6g — GitHub Advisory Database (CC-BY-4.0).