JAVA.SV.LLM.CLIENT.NOTIMEOUT
LLM client call without a timeout
The JAVA.SV.LLM.CLIENT.NOTIMEOUT checker identifies LLM client calls that do not configure a timeout.
Vulnerability and risk
LLM client calls without a timeout can consume threads and other resources longer than intended when a model response stalls.
Mitigation and prevention
Configure explicit timeouts for LLM client calls and handle timeout failures.
Vulnerable code example
Copy
import dev.langchain4j.model.openai.OpenAiChatModel;
public class Example {
private final OpenAiChatModel model = OpenAiChatModel.builder()
.apiKey(System.getenv("OPENAI_API_KEY"))
.modelName("gpt-4o-mini")
.build(); // no timeout configured
public String summarize(String prompt) {
return model.generate(prompt);
}
}
Fixed code example
Copy
import java.time.Duration;
import dev.langchain4j.model.openai.OpenAiChatModel;
public class Example {
private final OpenAiChatModel model = OpenAiChatModel.builder()
.apiKey(System.getenv("OPENAI_API_KEY"))
.modelName("gpt-4o-mini")
.timeout(Duration.ofSeconds(10))
.build();
public String summarize(String prompt) {
return model.generate(prompt);
}
}
External guidance
Security training
Application security training materials provided by Secure Code Warrior.