icon

We found results for “

CVE-2024-1455

Good to know:

icon
icon

Date: March 26, 2024

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

CWE-776

Top Fix

icon

Upgrade Version

Upgrade to version langchain-core - 0.1.34

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us