CVE-2025-5302

HIGH

Pypi Llama-index-core < 0.12.38 - Denial of Service

Title source: rule
STIX 2.1

Description

A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.

Scores

CVSS v3 8.6
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (2)
pypi/llama-index-core 0 - 0.12.38PyPI
run-llama/run-llama/llama_index unspecified - 0.12.38
Published Aug 25, 2025
Tracked Since Feb 18, 2026