CVE-2024-1455
MEDIUMA vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML...
Full analysis pending. Showing NVD description excerpt.
Affected Systems
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| langchain | pip | — | No patch |
Do you use langchain? You're affected.
Severity & Risk
Recommended Action
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Compliance Impact
Compliance analysis pending. Sign in for full compliance mapping when available.
Technical Details
NVD Description
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
Weaknesses (CWE)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References
- github.com/langchain-ai/langchain/commit/727d5023ce88e18e3074ef620a98137d26ff92a3 Patch
- huntr.com/bounties/4353571f-c70d-4bfd-ac08-3a89cecb45b6 Exploit 3rd Party
- github.com/langchain-ai/langchain/commit/727d5023ce88e18e3074ef620a98137d26ff92a3 Patch
- huntr.com/bounties/4353571f-c70d-4bfd-ac08-3a89cecb45b6 Exploit 3rd Party