CVE-2026-41481Patch(langchain / langchain-text-splitters)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch langchain langchain-text-splitters systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default). Because redirect targets were not revalidated, a URL pointing to an attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The response body is parsed and returned as Document objects to the calling application code. Whether this constitutes a data exfiltration path depends on the application: if it exposes Document contents (or derivatives) back to the requester who supplied the URL, sensitive data from internal endpoints could be leaked. Applications that store or process Documents internally without returning raw content to the requester are not directly exposed to data exfiltration through this issue. This vulnerability is fixed in 1.1.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain-text-splitters

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-25); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
langchain-text-splitters

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-24: 2Mentions · 2026-04-25: 3Mentions · 2026-05-10: 1Active Exploitation · 2026-04-25: 1Patch / Workaround · 2026-04-25: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 2Technical Details · 2026-05-10: 104-2404-2505-10
Signal classification4 categories
Patch
350.0%
Disclosure
116.7%
General
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure1General1
2026-04-253
Active Exploitation1Patch2
2026-05-101
Patch1
Full discourse6 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting langchain-ai langchain-text-splitters (CVE-2026-41481) https://vuldb.com/vuln/359575/cti

    Post summary

    Our CTI team reports multiple exploitation activities against langchain-text-splitters CVE-2026-41481, with no mention of a PoC or patch.

    0001177
    2.1K followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    CVE-2026-41481: langchain-text-splitters' HTMLHeaderTextSplitter.split_text_from_url() validated the URL, fetched it, and followed redirects without revalidating each hop. CWE-601 → CWE-918 chain. Patched in 1.1.2. Validate-then-fetch with redirects-on is the bug pattern.

    Post summary

    The post outlines a validate‑then‑fetch redirect vulnerability in langchain‑text‑splitters, lists relevant CWEs, and reports the fix coming in version 1.1.2.

    1000034
    66 followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    GPT-5.5 went GA on Thursday. By Friday morning, LangChain shipped TWO SSRF fixes — CVE-2026-41481 (text-splitters, redirect bypass) and CVE-2026-41488 (langchain-openai, DNS-rebind/TOCTOU). Same week. Concurrent, not sequential. The lesson isn't the model:

    Post summary

    LangChain released patches for two SSRF vulnerabilities, CVE-2026-41481 and CVE-2026-41488.

    1000053
    66 followersView on X
  • Rav@_MrDecentralize
    Patch

    LangChain CVE-2026-41481: The URL Was Validated. The Redirect Was Not. The URL passed the safety check. The redirect did not get one. CVE-2026-41481 was disclosed on April 24 against langchain-text-splitters versions before 1.1.2. CVSS 6.5. The HTMLHeaderTextSplitter.split_text_from_url function calls validate_safe_url on the input. Then it calls requests.get with redirects enabled by default. The 302 response and its Location header are never revalidated. An attacker hosts a benign-looking URL, returns a 302 pointing at 169.254.169.254, and the splitter quietly fetches cloud metadata into a Document object the application may surface back to the requester. The fix replaces requests.get with an SSRF-safe httpx transport that validates DNS results and pins connections to validated IPs on every request, including redirect targets. Most teams audit the agent. The pain is the framework one layer below it. LangChain is wired into thousands of agent deployments as a default. A single trusted helper that says "I check URLs" while the underlying HTTP library follows arbitrary redirects is the difference between a documented control and a real one. The validation ran. The validation was not enforced through the redirect chain. This is the second SSRF disclosure against a major AI inference and orchestration framework in the same week. LMDeploy was 7.5. LangChain is 6.5. Both of them collapse to "the framework fetched something on behalf of your agent and your perimeter never saw the egress." ### What it breaks - validate_safe_url creates a documented security control that does not function as documented. Teams that rely on framework-level URL validation as a control have a false positive in their control inventory. - Redirect chains from any attacker-controlled URL can point to 169.254.169.254 or internal RFC-1918 ranges. Cloud metadata, internal APIs, and Redis endpoints are all reachable through the validated-once path. - LangChain is embedded in thousands of agent deployments as a default dependency. A single patch gap across one transitive dependency exposes all downstream agents simultaneously. - Detection gap: The outbound request originates from the application server as a legitimate langchain-text-splitters call. No anomaly signal distinguishes an SSRF redirect from a normal document fetch in standard application logs. - Compliance exposure: SOC 2 CC6.6 requires that data processing is restricted to authorized purposes. Metadata exfiltration through a helper function that claims to validate URLs is an authorization control failure with no audit trail. ### What to do - Threat: Validated-Once SSRF via Redirect Chain: validate_safe_url ran on the input URL but the HTTP client followed 302 redirects without revalidation, meaning the security gate existed at the entry point only and the execution path had no boundary enforcement. - Start here: Upgrade langchain-text-splitters to 1.1.2 or later across all environments. Grep all agent codebases for HTMLHeaderTextSplitter.split_text_from_url usage before assuming patch coverage. [AI Agent Context Supply Chain Playbook](https://www.mrdecentralize.com/agentbook/playbook/playbook-context-supply-chain), 18 questions to stop data from becoming command. - Then: Audit all framework-level URL validation helpers across the dependency tree. Validate that redirect chains are blocked at the HTTP transport layer, not just at the input validation layer. - Operator connection: Any LangChain-based agent that fetches user-supplied URLs in a RAG or document-splitting pipeline is exposed. Scope review to any workflow where external URLs enter the context window. - Red team action: Run SSRF probe with a redirect chain from a controlled domain to 169.254.169.254 against all LangChain text-splitter endpoints. Confirm the fix is present by verifying httpx transport is the active HTTP client. ### Signal Breakdown - Architecture layer: L6 Tool and Integration Layer. - Attack surface: Framework URL validation helper that does not cover redirect targets, enabling SSRF into cloud metadata. - Playbooks: [AI Agent Context Supply Chain Playbook](https://www.mrdecentralize.com/agentbook/playbook/playbook-context-supply-chain). - Red team: SSRF redirect probe, httpx transport verification. - Frameworks: ASI09 (Supply Chain Vulnerabilities) / LLM02 (Sensitive Information Disclosure). **Source:** [GitLab Advisory Database, April 24, 2026](https://advisories.gitlab.com/pypi/langchain-text-splitters/GHSA-fv5p-p927-qmxr/) https://www.mrdecentralize.com/agentbook/playbook/playbook-context-supply-chain

    Post summary

    The advisory details a validated‑once SSRF flaw in LangChain and provides a clear patch path by upgrading to version 1.1.2, outlining the vulnerability type, impact, and mitigation.

    0000053
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41481 Server-Side Request Forgery via URL Redirect in LangChain Text Splitters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41481

    Post summary

    The passage announces CVE‑2026‑41481, describing it as an SSRF flaw involving URL redirects in LangChain text splitters, but provides no POCs, exploits, active exploitation, or remediation details.

    0000058
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41481 LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() vali… https://www.cve.org/CVERecord?id=CVE-2026-41481

    Post summary

    The post references CVE-2026-41481 in LangChain and links to the CVE record, but offers no further technical, exploit, or mitigation information.

    0000061
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain-text-splitters---

Explore more