Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2198788
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68356
Echo
6721
GHC
3
GIT
108079
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144358
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4295
Root
19534
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9498
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2564
PyPI/langchain-core
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
13 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-2563
PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates
13 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2562
PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
13 Jul
Fix available
Severity - 3.7 (Low)
PYSEC-2026-1070
PyPI/langchain-core-mcp
Malicious code in langchain-core-mcp (PyPI)
07 Jul
No fix available
PYSEC-2026-1518
PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-1517
PyPI/langchain-core
langchain-core allows unauthorized users to read arbitrary files from the host file system
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1519
PyPI/langchain-core
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
07 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-373
PyPI/langchain-core
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
29 Jun
Fix available
Severity - 9.3 (Critical)
MAL-2026-5318
PyPI/langchain-core-mcp
Malicious code in langchain-core-mcp (PyPI)
06 Jun
No fix available
GHSA-pjwx-r37v-7724
PyPI/langchain-core
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
08 May
Fix available
Severity - 8.2 (High)
GHSA-926x-3r5x-gfhw
PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates
08 Apr
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2193
PyPI/langchain-core
See record for full details
31 Mar
Fix available
Severity - 7.5 (High)
GHSA-qh6h-p6c9-ff54
PyPI/langchain-core
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
27 Mar
Fix available
Severity - 7.5 (High)
GHSA-2g6r-c272-w58r
PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
11 Feb
Fix available
Severity - 3.7 (Low)
GHSA-c67j-w6g6-q2cm
PyPI/langchain-core
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
23 Dec 2025
Fix available
Severity - 9.3 (Critical)
GHSA-6qv9-48xg-fc7f
PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
20 Nov 2025
Fix available
Severity - 8.3 (High)
Load more...
PyPI - OSV