VAITP Dataset

← Back to the dataset

CVE-2024-2965

DoS vulnerability in SitemapLoader due to infinite recursion in parsing.

  • CVSS 4.7
  • CWE-674
  • Resource Management
  • Remote

A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.

CVSS base score
4.7
Published
2024-06-06
OWASP
A10 Insufficient Logging & Monitoring
Orthogonal defect classification
Algorithm
Code defect classification
Incorrect Algorithm
Category
Resource Management
Subcategory
Resource Exhaustion
Accessibility scope
Remote
Impact
Denial of Service (DoS)
Fixed by upgrading
Yes

Solution

Implement a check to prevent recursive sitemap references in the `parse_sitemap` method. Upgrade to the latest version of `langchain-ai/langchain` where this issue is fixed.

Vulnerable code sample

class SitemapLoader:
    def parse_sitemap(self, url):
        self.parse_sitemap(url)

loader = SitemapLoader()
loader.parse_sitemap('http://example.com/sitemap.xml')

Patched code sample

class SitemapLoader:
    def __init__(self):
        self.visited_urls = set()

    def parse_sitemap(self, url):
        if url in self.visited_urls:
            raise ValueError("Detected potential infinite recursion for URL: {}".format(url))
        
        self.visited_urls.add(url)
        
        self.parse_sitemap(url)

loader = SitemapLoader()
try:
    loader.parse_sitemap('http://example.com/sitemap.xml')
except ValueError as e:
    print(e)

Payload

sitemap_url = 'http://example.com/sitemap.xml'
loader = SitemapLoader()
loader.parse_sitemap(sitemap_url)  # This URL would refer to itself, causing infinite recursion

Cite this entry

@misc{vaitp:cve20242965,
  title        = {{DoS vulnerability in SitemapLoader due to infinite recursion in parsing.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2024},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2024-2965},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2024-2965/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::