Junglewise Threat Intelligence

CVE-2025-5472: PYSEC-2026-1559 - LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

CVE-2025-5472 · Severity: low · CVSS 3 · Published 2026-07-07

Technologies: llama-index (PyPI), llama-index-core (PyPI). Vendors: PyPI.

Executive brief

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

Affected products

  • PyPI llama-index
  • PyPI llama-index-core

Related threats