CVE-2024-2965
DoS vulnerability in SitemapLoader due to infinite recursion in parsing.
- CVSS 4.7
- CWE-674
- Resource Management
- Remote
A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.
- CWE
- CWE-674
- CVSS base score
- 4.7
- Published
- 2024-06-06
- OWASP
- A10 Insufficient Logging & Monitoring
- Orthogonal defect classification
- Algorithm
- Code defect classification
- Incorrect Algorithm
- Category
- Resource Management
- Subcategory
- Resource Exhaustion
- Accessibility scope
- Remote
- Impact
- Denial of Service (DoS)
- Fixed by upgrading
- Yes
Solution
Implement a check to prevent recursive sitemap references in the `parse_sitemap` method. Upgrade to the latest version of `langchain-ai/langchain` where this issue is fixed.
Vulnerable code sample
class SitemapLoader:
def parse_sitemap(self, url):
self.parse_sitemap(url)
loader = SitemapLoader()
loader.parse_sitemap('http://example.com/sitemap.xml')Patched code sample
class SitemapLoader:
def __init__(self):
self.visited_urls = set()
def parse_sitemap(self, url):
if url in self.visited_urls:
raise ValueError("Detected potential infinite recursion for URL: {}".format(url))
self.visited_urls.add(url)
self.parse_sitemap(url)
loader = SitemapLoader()
try:
loader.parse_sitemap('http://example.com/sitemap.xml')
except ValueError as e:
print(e)Payload
sitemap_url = 'http://example.com/sitemap.xml'
loader = SitemapLoader()
loader.parse_sitemap(sitemap_url) # This URL would refer to itself, causing infinite recursion
Cite this entry
@misc{vaitp:cve20242965,
title = {{DoS vulnerability in SitemapLoader due to infinite recursion in parsing.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2024},
note = {VAITP Python Vulnerability Dataset, entry CVE-2024-2965},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2024-2965/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
