ZeroHour

CVE-2024-1455

PoC
CVSS 3.1
5.9 medium
EPSS
<1%p54
Published
()
Modified
Description

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

Vendors
langchain
Products
langchain
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.