CVE-2025-6208: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-6208 is an uncontrolled memory consumption vulnerability in the SimpleDirectoryReader component of llama_index.core (run-llama/llama_index). The flaw exists in version 0.12.23 and is resolved in version 0.12.41. It carries a CVSS v3.0 base score of 5.3 (Medium), with no authentication or user interaction required for exploitation (Red Hat Advisory, Red Hat Bugzilla). The vulnerability was disclosed on February 2, 2026, and was reported via the Huntr bug bounty platform (ENISA EUVD).

Technical details

The root cause is a resource management flaw classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-1050 (Excessive Platform Resource Consumption within a Loop). In the vulnerable code path, SimpleDirectoryReader._add_files() uses fs.glob() to enumerate all files in a directory before applying the user-specified num_files_limit parameter — meaning all file references are loaded into memory first, and the limit is only enforced afterward via a list slice. The fix (commit 53614e2) replaces the glob-based approach with an incremental fs.walk() loop that breaks as soon as the file count exceeds the specified limit, preventing unbounded memory accumulation (GitHub Commit, Red Hat Bugzilla).

Impact

Successful exploitation causes memory exhaustion and degraded performance on systems running the affected llama_index.core version, resulting in denial of service (DoS) conditions. There is no confidentiality or integrity impact — the vulnerability is limited to availability. The impact is most severe in resource-constrained environments such as containerized deployments, cloud instances, or embedded systems where memory is limited (Red Hat Advisory, GitHub Commit).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date (Red Hat Advisory). The vulnerability is network-accessible, requires no privileges or user interaction, and has low attack complexity, making it straightforward to trigger if an attacker can influence the directories processed by SimpleDirectoryReader. The EPSS score is approximately 0.042% (very low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Identify target: Locate a service or application that uses llama_index.core version 0.12.23 and exposes SimpleDirectoryReader functionality — either directly via an API endpoint or indirectly through a document ingestion pipeline.
  2. Prepare a large directory: Create or reference a directory containing a very large number of files (e.g., thousands of small files) that the target application will be directed to process.
  3. Trigger directory loading: Submit a request to the application that causes SimpleDirectoryReader to process the large directory, for example by supplying the directory path as input to a document ingestion or indexing endpoint.
  4. Cause memory exhaustion: Because num_files_limit is applied only after all file references are loaded into memory via fs.glob(), the server's memory is consumed proportionally to the total number of files in the directory, regardless of the configured limit — leading to memory exhaustion and potential DoS (GitHub Commit, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Sudden spikes in memory usage logged by the application or container runtime coinciding with SimpleDirectoryReader invocations; application crash or OOM-killer events in system logs (dmesg, /var/log/syslog) referencing the Python process.
  • Process: Python process consuming abnormally high memory (observable via top, htop, or container metrics) when processing directory ingestion requests.
  • Network: Unusual or repeated API requests to document ingestion endpoints with large or deeply nested directory paths as input parameters.
  • Application: Log entries from llama_index indicating large numbers of files being enumerated (e.g., [SimpleDirectoryReader] Total files added: <very large number>) before an OOM or crash event (GitHub Commit).

Mitigation and workarounds

Upgrade llama_index.core to version 0.12.41 or later, which enforces num_files_limit during file enumeration rather than after loading (GitHub Commit, Red Hat Bugzilla). For organizations unable to upgrade immediately, implement the following mitigations: restrict the directories accessible to SimpleDirectoryReader to those containing only necessary files; apply container or OS-level memory limits (e.g., Docker --memory flag) to bound the impact of memory exhaustion; and add network-level controls to limit which clients can trigger document ingestion workflows (Red Hat Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management