Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2g6r-c272-w58r | LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages |
Tue, 17 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain Core |
|
| CPEs | cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Langchain
Langchain langchain Core |
Thu, 12 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain-ai
Langchain-ai langchain |
|
| Vendors & Products |
Langchain-ai
Langchain-ai langchain |
|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed in 1.2.11. | |
| Title | LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-11T21:26:34.029Z
Reserved: 2026-02-09T21:36:29.554Z
Link: CVE-2026-26013
Updated: 2026-02-11T21:26:27.378Z
Status : Analyzed
Published: 2026-02-10T22:17:00.453
Modified: 2026-03-17T20:30:07.960
Link: CVE-2026-26013
OpenCVE Enrichment
Updated: 2026-04-18T12:45:45Z
Github GHSA