LlamaIndex Denial-of-Service Vulnerability (CVE-2024-12704)

A denial-of-service vulnerability was found in the LangChainLLM class of LlamaIndex. The flaw allowed an infinite loop to occur, rendering the system unresponsive.

LlamaIndex · Incident Mar 20, 2025 · Indexed Jun 16, 2026 · 3 sources

Records by entity: LlamaIndex

The short version

A vulnerability in LlamaIndex's LangChainLLM class caused an infinite loop and denial of service when processing certain incorrect input types.

An unhandled thread termination in the LangChainLLM class led to an infinite loop in the response generator.
What
A denial-of-service vulnerability was found in the LangChainLLM class of LlamaIndex.
Incident date
Mar 20, 2025
Who
LlamaIndex
Failure mode
Brand & Safety Incident
AI surface
Agentic Workflow
Severity
High

What happened

LlamaIndex's LangChainLLM class in version 0.12.5 contained a vulnerability that could be exploited to cause a denial-of-service attack. The issue was publicly disclosed as CVE-2024-12704 and resolved in version 0.12.6. This vulnerability allowed an attacker to cause the process to hang indefinitely.

What broke inside the model

Failure path · mode profile · Brand & Safety Incident
  1. 01 · TriggerA user prompts the model in public view.
  2. 02 · Model stepThe model produces unsafe or off-brand output.
  3. 03 · Control gapNo filter holds the line before publish.
  4. 04 · FailureThe output goes public unchecked.
  5. 05 · ConsequenceA reputational or safety incident lands.

A contained signal crosses into output that goes public.

The stream_complete method lacked exception handling for threads that terminated abnormally before the _llm.predict call. This resulted in an infinite loop within the get_response_gen function of the StreamingGeneratorCallbackHandler class when an incorrect input type was provided.

Public visibilityHigh
Regulatory exposureNone
Customer impactFew customers
Financial impactUnknown
Time to disclosureDays
  1. PrimaryCVE-2024-12704 - NVDnvd.nist.gov
  2. PrimaryLlamaIndex Improper Handling of Exceptional Conditions vulnerabilitygithub.com
  3. PressSecurity Risks of LLM Frameworks with Case Studiesflatt.tech
Permalinkhttps://failureindex.ai/failures/llamaindex-denial-service-vulnerability-cve-2024
CitationAI Failure Index. "LlamaIndex Denial-of-Service Vulnerability (CVE-2024-12704)" (FI-0566). Realm Labs. https://failureindex.ai/failures/llamaindex-denial-service-vulnerability-cve-2024 (indexed Jun 16, 2026).
Share cardA branded image of this record for posts and slides.

Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0566. Full dataset at /data.

Note from Realm Labs, the Index steward

How Realm would have caught this

Controls for this failure mode
  • Prism
  • OmniGuard
  • AI Detection & Response (AIDR)

Realm watches the model's internal state for the signature of unsafe or off-brand generation and can block or reroute the output before it becomes public, in real time rather than after it has been screenshotted.