Skip to content
Langchain Community SSRF Vulnerability Exposes Internal Services

Langchain Community SSRF Vulnerability Exposes Internal Services

First seen 17 Feb 2026, 08:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-26019, has been discovered in the langchain/community package, affecting versions up to 1.1.13. This flaw has a moderate severity rating and can potentially expose sensitive cloud metadata and internal infrastructure due to its origin in the RecursiveUrlLoader class, which performs recursive web crawling.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 191d ago How this analysis works

Timeline

2026-02-17
CVE-2026-26019 published
2026-02-17
Vulnerability identified in langchain/community package
Recent
Details about the flaw and its impact released

More articles in this cluster (4)

Following this threat?

Track LangChain and CVE-2026-26019 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed