CVE-2026-41488Disclosure(langchain / langchain-openai)

LOWCVSS 3.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch langchain langchain-openai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain-openai

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-25)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
langchain-openai

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-24: 1Mentions · 2026-04-25: 3Patch / Workaround · 2026-04-25: 2Technical Details · 2026-04-25: 304-2404-25
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-253
Disclosure1Patch2
Full discourse4 posts
  • Sattyam Jain@Sattyamjjain
    Patch

    CVE-2026-41488: langchain-openai's _url_to_size() resolved the host, validated the IP, then fetched through a separate code path that triggered a second resolution. TOCTOU window. CVSS 3.1 (Pillow consumes the response, no exfil) but the class generalizes. Patched in 1.1.14.

    Post summary

    The post details CVE-2026-41488 with technical specifics and indicates that a patch (v1.1.14) has been issued.

    1000034
    66 followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    GPT-5.5 went GA on Thursday. By Friday morning, LangChain shipped TWO SSRF fixes — CVE-2026-41481 (text-splitters, redirect bypass) and CVE-2026-41488 (langchain-openai, DNS-rebind/TOCTOU). Same week. Concurrent, not sequential. The lesson isn't the model:

    Post summary

    LangChain released fixes for two SSRF-related CVEs (CVE-2026‑41481 and CVE-2026‑41488) within the same week, providing details on the vulnerabilities and the patch.

    1000053
    66 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41488 DNS Rebinding Vulnerability in LangChain OpenAI Prior to Version 1.1.14 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41488

    Post summary

    The text announces a DNS rebinding vulnerability (CVE‑2026‑41488) affecting LangChain OpenAI before version 1.1.14, with no PoC, exploit, patch, or active exploitation details given.

    0000063
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41488 LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_mess… https://www.cve.org/CVERecord?id=CVE-2026-41488

    Post summary

    The snippet references CVE-2026-41488 as a vulnerability in the LangChain langchain-openai package before version 1.1.14, affecting a helper function used during token analysis, but it provides no further detail.

    0000059
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain-openai---

Explore more