Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mphv-75cg-56wg | LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader |
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain Community |
|
| CPEs | cpe:2.3:a:langchain:langchain_community:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Langchain
Langchain langchain Community |
Thu, 26 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain-ai
Langchain-ai langchainjs |
|
| Vendors & Products |
Langchain-ai
Langchain-ai langchainjs |
Thu, 26 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying fetch to follow redirects automatically, which permits a transition from a safe public URL to an internal or metadata endpoint without revalidation. This is a bypass of the SSRF protections introduced in 1.1.14 (CVE-2026-26019). Users should upgrade to `@langchain/community` 1.1.18, which validates every redirect hop by disabling automatic redirects and re-validating `Location` targets before following them. In this version, automatic redirects are disabled (`redirect: "manual"`), each 3xx `Location` is resolved and validated with `validateSafeUrl()` before the next request, and a maximum redirect limit prevents infinite loops. | |
| Title | LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T18:42:52.277Z
Reserved: 2026-02-24T02:31:33.265Z
Link: CVE-2026-27795
Updated: 2026-02-25T18:42:46.808Z
Status : Analyzed
Published: 2026-02-25T18:23:41.153
Modified: 2026-04-13T14:15:35.920
Link: CVE-2026-27795
OpenCVE Enrichment
Updated: 2026-04-17T15:15:21Z
Github GHSA