CVE-2025-5302

HIGH

llama-index-core < 0.12.38 - Denial of Service via JSONReader Recursion

Title source: llm
STIX 2.1

Description

A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38.

Scores

CVSS v3 8.6
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (2)
pypi/llama-index-core 0 - 0.12.38PyPI
run-llama/run-llama/llama_index unspecified - 0.12.38
Published Aug 25, 2025
Tracked Since Feb 18, 2026