SOURCE-LINKED INTELLIGENCE
GHSA-3hjh-jh2h-vrg6: Denial of service in langchain-community
Denial of service in `SitemapLoader` Document Loader in the `langchain-community` package, affecting versions below 0.2.5. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on t
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-06-06T21:30:36.000Z
- OSV AI package advisories · 2024-06-06T19:15:00.000Z
First collected: 2026-09-19T20:26:55.867Z. This is not the publication date.