Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 13 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Run-llama
Run-llama llama Index |
|
| Vendors & Products |
Run-llama
Run-llama llama Index |
Mon, 12 Jan 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via vn.run_sql() without enforcing query execution limits In downstream deployments where untrusted users can supply prompts, an attacker can trigger expensive or unbounded SQL operations that exhaust CPU or memory resources, resulting in a denial-of-service condition. The vulnerable execution path occurs in llama_index/packs/vanna/base.py within custom_query(). | |
| Title | LlamaIndex <= 0.12.2 VannaQueryEngine SQL Execution Allows Resource Exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T17:18:28.994Z
Reserved: 2026-01-09T20:28:41.285Z
Link: CVE-2024-58339
Updated: 2026-01-13T17:18:26.203Z
Status : Awaiting Analysis
Published: 2026-01-12T23:15:51.630
Modified: 2026-01-13T14:03:18.990
Link: CVE-2024-58339
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:27:13Z