Denial of service in langchain-community
Medium4.2CVE-2024-2965 · Published Jun 6, 2024 · updated Jul 13, 2026
Denial of service in `SitemapLoader` Document Loader in the `langchain-community` package, affecting versions below 0.2.5. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langchain PyPI | < 0.2.5 | 0.2.5 |
| langchain-community PyPI | < 0.2.5 | 0.2.5 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400, CWE-674
- Also known as
- CVE-2024-2965, PYSEC-2024-118, PYSEC-2026-2561
- nvd.nist.gov/vuln/detail/CVE-2024-2965
- github.com/langchain-ai/langchain/pull/22903
- github.com/langchain-ai/langchain/commit/73c42306745b0831aa6fe7fe4eeb70d2c2d87a82
- github.com/langchain-ai/langchain/commit/9a877c7adbd06f90a2518152f65b562bd90487cc
- github.com/langchain-ai/langchain
- github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-118.yaml
- huntr.com/bounties/90b0776d-9fa6-4841-aac4-09fde5918cae
More LangChain advisories
All LangChain| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 152024 | langchain-experimental vulnerable to Arbitrary Code Execution | Critical8.5 | 0.0.21 |
| Jun 162024 | langchain_experimental Code Execution via Python REPL access | High7.8 | 0.0.61 |
| Jun 62024 | Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever | Medium4.8 | 0.2.9 |
| Apr 162024 | langchain vulnerable to path traversal | Medium6.5 | 0.0.353 |
| Mar 262024 | LangChain's XMLOutputParser vulnerable to XML Entity Expansion | Medium5.9 | 0.1.35 |
| Mar 42024 | LangChain directory traversal vulnerability | Low | 0.0.339+1 more |