Количество 2
Количество 2
CVE-2024-1455
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
GHSA-q84m-rmw3-4382
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-1455 A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS). | CVSS3: 5.9 | 0% Низкий | почти 2 года назад | |
GHSA-q84m-rmw3-4382 LangChain's XMLOutputParser vulnerable to XML Entity Expansion | CVSS3: 5.9 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу