
CVE-2026-41488: langchain-openai's _url_to_size() resolved the host, validated the IP, then fetched through a separate code path that triggered a second resolution. TOCTOU window. CVSS 3.1 (Pillow consumes the response, no exfil) but the class generalizes. Patched in 1.1.14.
Post summary
The post details CVE-2026-41488 with technical specifics and indicates that a patch (v1.1.14) has been issued.


