Langchain-core
This hub aggregates every CVE we track for Langchain-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM2LOW1HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
1
0
1
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Langchain-core.
- CVE-2026-26013LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages3.7
- CVE-2025-68664LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs9.3
- CVE-2024-10940Exposure of Sensitive System Information via ImagePromptTemplate in langchain-ai/langchain5.3
- CVE-2024-1455Billion Laughs Attack leading to DoS in langchain-ai/langchain5.9
- CVE-2024-28088LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading ...8.1
Product normalization is registry-driven with AI assist and human review. How it works