Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2184320
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17131
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1019778
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67341
Echo
6542
GHC
3
GIT
106316
GitHub Actions
55
Go
9147
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6200
Maven
6998
MinimOS
142693
npm
228436
NuGet
1860
opam
29
openEuler
8674
openSUSE
14325
OSS-Fuzz
4003
Packagist
7036
Pub
11
PyPI
25074
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9207
Ubuntu
64326
VSCode
21
Wolfi
287370
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2564
PyPI/langchain-core
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
13 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-2563
PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates
13 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2562
PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
13 Jul
Fix available
Severity - 3.7 (Low)
PYSEC-2026-1070
PyPI/langchain-core-mcp
Malicious code in langchain-core-mcp (PyPI)
07 Jul
No fix available
PYSEC-2026-1518
PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-1517
PyPI/langchain-core
langchain-core allows unauthorized users to read arbitrary files from the host file system
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1519
PyPI/langchain-core
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
07 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-373
PyPI/langchain-core
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
29 Jun
Fix available
Severity - 9.3 (Critical)
MAL-2026-5318
PyPI/langchain-core-mcp
Malicious code in langchain-core-mcp (PyPI)
06 Jun
No fix available
GHSA-pjwx-r37v-7724
PyPI/langchain-core
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
08 May
Fix available
Severity - 8.2 (High)
GHSA-926x-3r5x-gfhw
PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates
08 Apr
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-2193
PyPI/langchain-core
See record for full details
31 Mar
Fix available
Severity - 7.5 (High)
GHSA-qh6h-p6c9-ff54
PyPI/langchain-core
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
27 Mar
Fix available
Severity - 7.5 (High)
GHSA-2g6r-c272-w58r
PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
11 Feb
Fix available
Severity - 3.7 (Low)
GHSA-c67j-w6g6-q2cm
PyPI/langchain-core
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
23 Dec 2025
Fix available
Severity - 9.3 (Critical)
GHSA-6qv9-48xg-fc7f
PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
20 Nov 2025
Fix available
Severity - 8.3 (High)
Load more...
PyPI - OSV