CVE-2024-1455: medium-severity vulnerability in langchain-ai/langchain
Billion Laughs Attack leading to DoS in langchain-ai/langchain
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
langchain-ai · langchain-ai/langchainRelated CVEs — langchain-ai/langchain
In the same product, most dangerous first.
CVE-2025-2828HIGHSSRF Vulnerability in RequestsToolkit in langchain-ai/langchainEPSS 21.0%CVE-2024-8309MEDIUMSQL Injection in langchain-ai/langchainEPSS 13.7%CVE-2024-3571MEDIUMPath Traversal in langchain-ai/langchainEPSS 1.9%CVE-2025-6984HIGHSensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchainEPSS 1.6%CVE-2024-3095MEDIUMSSRF in Langchain Web Research Retriever in langchain-ai/langchainEPSS 0.7%CVE-2024-0243LOWServer-side Request Forgery In Recursive URL LoaderEPSS 0.5%