PYSEC-2026-1554

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/llama-index/PYSEC-2026-1554.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1554
Aliases
Published
2026-07-07T16:02:52.183037Z
Modified
2026-07-07T17:46:53.695420508Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
LlamaIndex Vulnerable to Denial of Service (DoS)
Details

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llamaindex project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the maxdepth parameter in the getarticleurls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.

References

Affected packages

PyPI / llama-index

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.15
Fixed
0.12.21

Affected versions

0.*
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.20

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/llama-index/PYSEC-2026-1554.yaml"