CVE-2025-5302High· 8.6▾ TwilightLlamaIndex affected by a Denial of Service (DOS) in JSONReader
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.
llama-index-core < 0.12.38Upgrade to a patched release:
llama-index-core 0.12.38Connected by shared product, vendor, weakness, or advisory.
CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-3108Medium· 5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2024-12704High· 7.5LlamaIndex Improper Handling of Exceptional Conditions vulnerability
CVE-2025-7647High· 7.3llama-index-core insecurely handles temporary files
CVE-2025-6208Medium· 5.3llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function