langchain-ai Vulnerabilities and Affected Products
Vulnerabilities associated with langchain-openai.
Products
Clear product- langchain-ai/langchain12 vulnerabilities
- langchain9 vulnerabilities
- langgraph7 vulnerabilities
- langsmith-sdk5 vulnerabilities
- langchainjs4 vulnerabilities
- langchain-ai/langchainjs2 vulnerabilities
- langchain-ai\/langchain2 vulnerabilities
- langgraphjs2 vulnerabilities
- helm1 vulnerability
- langchain-ai1 vulnerability
- langchain-ai\/langchainjs1 vulnerability
- langchain-anthropic1 vulnerability
- langchain-openai1 vulnerability
- langchain-sdk1 vulnerability
- langchain-text-splitters1 vulnerability
- langgraph-checkpoint1 vulnerability
- langgraph-checkpoint-postgres1 vulnerability
- langgraph-checkpoint-sqlite1 vulnerability
- langraph-checkpoint1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebindingLangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch. CWE-918Apr 24, 2026 | CVSS3.1v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |