---
id: CVE-2024-12704
aliases:
  - GHSA-j3wr-m6xh-64hg
  - PYSEC-2026-1563
title: LlamaIndex Improper Handling of Exceptional Conditions vulnerability
summary: LlamaIndex Improper Handling of Exceptional Conditions vulnerability
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: llama-index-core
product: llama-index-core
ecosystem: pip
affected:
  - llama-index-core < 0.12.6
patched:
  - llama-index-core 0.12.6
published: '2025-03-20'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-j3wr-m6xh-64hg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-12704'
  - url: >-
      https://github.com/run-llama/llama_index/commit/d1ecfb77578d089cbe66728f18f635c09aa32a05
  - url: 'https://github.com/run-llama/llama_index'
  - url: 'https://huntr.com/bounties/a0b638fd-21c6-4ba7-b381-6ab98472a02a'
tags:
  - osv
  - pip
epss: 0.00815
epssPercentile: 0.55591
ingestedAt: '2026-07-08T18:25:50.556Z'
---

## Overview

A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a thread and retrieves the result via the get_response_gen method of the StreamingGeneratorCallbackHandler class. If the thread terminates abnormally before the _llm.predict is executed, there is no exception handling for this case, leading to an infinite loop in the get_response_gen function. This can be triggered by providing an input of an incorrect type, causing the thread to terminate and the process to continue running indefinitely.

## Affected packages

- `llama-index-core < 0.12.6`

## Remediation

Upgrade to a patched release:

- `llama-index-core 0.12.6`
