Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3225

Опубликовано: 07 июл. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2376764llama-index: XML Entity Expansion in llama_index

EPSS

Процентиль: 24%
0.00079
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.

CVSS3: 7.5
github
около 1 месяца назад

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость фреймворка для работы с большими языковыми моделями (LLM) LlamaIndex, связанная с неправильным ограничением рекурсивных ссылок на сущности в DTD, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 24%
0.00079
Низкий

5.3 Medium

CVSS3