CVE-2026-41488 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_fro…
Low CVSS: 3.1

CVE-2026-41488

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.
Vendor
-
Product
-
CWE
CWE-918
Yayın Tarihi
2026-04-24 21:16:19
Güncelleme
2026-04-24 21:16:19
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar