Executive brief
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Affected products
- PyPI llama-index
- PyPI llama-index-core
Junglewise Threat Intelligence
CVE-2025-5472 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: llama-index (PyPI), llama-index-core (PyPI). Vendors: PyPI.
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing