#VU123068 Expected behavior violation in llama_index - CVE-2025-6211
Published: February 19, 2026
llama_index
run-llama (LlamaIndex)
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the DocugamiReader class of the run-llama/llama_index repository involves the use of MD5 hashing to generate IDs for document chunks. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.