CVE-2026-26019Disclosure(langchain / langchain_community)

LOWCVSS 4.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch langchain langchain_community systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting URL. Its preventOutside option (enabled by default) is intended to restrict crawling to the same site as the base URL. The implementation used String.startsWith() to compare URLs, which does not perform semantic URL validation. An attacker who controls content on a crawled page could include links to domains that share a string prefix with the target, causing the crawler to follow links to attacker-controlled or internal infrastructure. Additionally, the crawler performed no validation against private or reserved IP addresses. A crawled page could include links targeting cloud metadata services, localhost, or RFC 1918 addresses, and the crawler would fetch them without restriction. This vulnerability is fixed in 1.1.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain_community

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-17); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
langchain_community

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-02-17: 2Mentions · 2026-02-24: 1Mentions · 2026-03-04: 1Mentions · 2026-06-13: 1Patch / Workaround · 2026-02-17: 2Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-24: 1Technical Details · 2026-03-04: 102-1102-1202-1702-2403-0406-13
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-121
Disclosure1
2026-02-172
Disclosure1Patch1
2026-02-241
Patch1
2026-03-041
Disclosure1
2026-06-131
Patch1
Full discourse7 posts
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 SSRF Alert in LangChain! CVE-2026-26019: A naive startsWith() check in RecursiveUrlLoader lets attackers bypass crawl restrictions and reach internal network assets, turning a single injected link into SSRF. We cover the root cause, exploitation, and the patch. Full breakdown 👇 https://blog.ostorlab.co/cve-2026-26019-ssrf-langchain.html

    Post summary

    The post provides an overview of the newly disclosed CVE‑2026‑26019, detailing the technical flaw, exploitation method, and available patch.

    01022107
    586 followersView on X
  • MX3 Dev@Mx3Dev
    Patch

    @mem0ai Security & dependencies → Upgrade @langchain/community to fix CVE-2026-27795 and CVE-2026-26019 → Resolve all medium Dependabot alerts via pnpm overrides.

    Post summary

    The tweet recommends upgrading the @langchain/community package to remediate CVE‑2026‑27795 and CVE‑2026‑26019, indicating a need for a patch.

    1000034
    123 followersView on X
  • iototsecnews@iototsecnews
    Patch

    LangChain の脆弱性 CVE-2026-26019 が FIX:脅威アクターが制御するドメインからの SSRF 攻撃 https://iototsecnews.jp/2026/02/17/langchain-community-ssrf-bypass-vulnerability-exposes-internal-services-to-unauthorized-access/ 脆弱性 CVE-2026-26019 (CVSS 6.1) は、@langchain/community の RecursiveUrlLoader における URL 検証の不備に起因します。原因は、オリジン確認において、厳密な URL 解析ではなく String.startsWith() による文字列比較へ依存していた点にあります。そのため、接頭辞が一致するドメインで制限を回避し、さらに旧バージョンではプライベート IP やクラウド・メタデータ検証も不足していました。結果として、内部ネットワークや AWS/Google Cloud/Azure のメタデータ取得が可能となる状態でした。バージョン 1.1.14 では厳格なオリジン検証と SSRF 防御が追加されています。 #Community #CVE202626019 #LangChain #Vulnerability

    Post summary

    The post announces the CVE‑2026‑26019 SSRF vulnerability in LangChain’s RecursiveUrlLoader, details the technical flaw, and notes that version 1.1.14 includes a patch to mitigate the issue.

    01000131
    485 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26019 LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursivel… https://www.cve.org/CVERecord?id=CVE-2026-26019

    Post summary

    The text only references CVE‑2026‑26019 and provides a link to its CVE record, offering no additional details.

    00010177
    56.5K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🔍 𝐋𝐚𝐭𝐞𝐬𝐭 𝐂𝐕𝐄 𝐛𝐫𝐞𝐚𝐤𝐝𝐨𝐰𝐧 𝐚𝐯𝐚𝐢𝐥𝐚𝐛𝐥𝐞 𝐧𝐨𝐰! SSRF in LangChain lets intruders access sensitive internal services. Learn how CVE-2026-26019 threatens AI workflows and what to patch now. 🌐 Explore the write-up → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/langchain-ssrf-vulnerability/ What’s your take? Share with us!

    Post summary

    The post announces the SSRF CVE-2026-26019 in LangChain and urges readers to patch the issue, highlighting the vulnerability’s impact on AI workflows.

    0000045
    64 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 LangChain Community SSRF Bypass Lets Attackers Reach Internal Services & Cloud Metadata (CVE-2026-26019) A flaw in @langchain/community’s RecursiveUrlLoader (≤1.1.13) lets crafted URLs bypass “same-domain” checks and reach internal/private addresses, enabling SSRF to endpoints like 169.254.169.254 to leak cloud metadata/credentials and probe internal services. Fixed in 1.1.14 by strict origin validation and new SSRF filters that block private/loopback/metadata ranges. 🎯 Target: Global/AI Apps & Cloud Environments (LangChain Users) #️⃣ Category: #Vulnerability #BlueTeam #AI_Threats 🔗 URL: https://cybersecuritynews.com/langchain-community-ssrf-bypass-vulnerability/

    Post summary

    The text announces an SSRF bypass in LangChain's RecursiveUrlLoader that could expose internal services and cloud metadata, and notes that the issue is fixed in version 1.1.14.

    0000055
    176 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26019: Spider in the Web: Escaping LangChain's Crawler Sandbox via SSRF A logic flaw in the LangChain JS `@langchain/community` package allows for Server-Side Request Forgery (SSRF) within the `RecursiveUrlLoader`. By bypassing a weak string-... https://cvereports.com/reports/CVE-2026-26019

    Post summary

    CVE-2026-26019 is an SSRF vulnerability stemming from a logic flaw in LangChain's RecursiveUrlLoader within the @langchain/community package.

    0000047
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain_community-node.js-

Explore more