XMLOutputParser Vulnerability in LangChain Could Lead to Availability Compromise
CVE-2024-1455

5.9MEDIUM

Key Information:

Vendor
CVE Published:
26 March 2024

What is CVE-2024-1455?

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

Affected Version(s)

langchain-ai/langchain < 0.1.35

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.