Sploitus

CVE-2024-58340

No indexed exploits for CVE-2024-58340 yet

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition.

Affected products
Langchain
Langchain
≤ 0.3.1
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
7.5 HIGH
EPSS
0.4% (34th percentile)
Weakness
CWE-1333
NVD status
Analyzed
Published
2026-01-12
CVE-2024-58340 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-58340 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-58340 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.