JAVA.SV.LLM.CLIENT.NOTIMEOUT

LLM client call without a timeout

The JAVA.SV.LLM.CLIENT.NOTIMEOUT checker identifies LLM client calls that do not configure a timeout.

Vulnerability and risk

LLM client calls without a timeout can consume threads and other resources longer than intended when a model response stalls.

Mitigation and prevention

Configure explicit timeouts for LLM client calls and handle timeout failures.

Vulnerable code example

Copy
import dev.langchain4j.model.openai.OpenAiChatModel;

public class Example {
    private final OpenAiChatModel model = OpenAiChatModel.builder()
        .apiKey(System.getenv("OPENAI_API_KEY"))
        .modelName("gpt-4o-mini")
        .build(); // no timeout configured

    public String summarize(String prompt) {
        return model.generate(prompt);
    }
}

Fixed code example

Copy
import java.time.Duration;
import dev.langchain4j.model.openai.OpenAiChatModel;

public class Example {
    private final OpenAiChatModel model = OpenAiChatModel.builder()
        .apiKey(System.getenv("OPENAI_API_KEY"))
        .modelName("gpt-4o-mini")
        .timeout(Duration.ofSeconds(10))
        .build();

    public String summarize(String prompt) {
        return model.generate(prompt);
    }
}

Security training

Application security training materials provided by Secure Code Warrior.