Логотип exploitDog
bind:CVE-2024-1455
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-1455

Количество 2

Количество 2

nvd логотип

CVE-2024-1455

почти 2 года назад

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-q84m-rmw3-4382

почти 2 года назад

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-1455

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-q84m-rmw3-4382

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

CVSS3: 5.9
0%
Низкий
почти 2 года назад

Уязвимостей на страницу