CVE-2024-1455

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-26 14:15

Updated : 2024-04-16 12:15


NVD link : CVE-2024-1455

Mitre link : CVE-2024-1455

CVE.ORG link : CVE-2024-1455


JSON object : View

Products Affected

No product.

CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')