CVE-2024-1455

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
Configurations

Configuration 1 (hide)

cpe:2.3:a:langchain:langchain:*:*:*:*:*:*:*:*

History

30 Jul 2025, 20:06

Type Values Removed Values Added
First Time Langchain
Langchain langchain
References () https://github.com/langchain-ai/langchain/commit/727d5023ce88e18e3074ef620a98137d26ff92a3 - () https://github.com/langchain-ai/langchain/commit/727d5023ce88e18e3074ef620a98137d26ff92a3 - Patch
References () https://huntr.com/bounties/4353571f-c70d-4bfd-ac08-3a89cecb45b6 - () https://huntr.com/bounties/4353571f-c70d-4bfd-ac08-3a89cecb45b6 - Exploit, Third Party Advisory
CPE cpe:2.3:a:langchain:langchain:*:*:*:*:*:*:*:*

Information

Published : 2024-03-26 14:15

Updated : 2025-07-30 20:06


NVD link : CVE-2024-1455

Mitre link : CVE-2024-1455

CVE.ORG link : CVE-2024-1455


JSON object : View

Products Affected

langchain

  • langchain
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')