Executive brief
LangChain is a framework used to build applications powered by large language models (LLMs). A security flaw in its text-processing component allows attackers to trick the system into accessing internal network resources, such as private servers or cloud metadata services, that should be restricted. If an application returns the processed content to the user, this could lead to the theft of sensitive internal data or configuration information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `HTMLHeaderTextSplitter.split_text_from_url()` function of the `langchain-text-splitters` library. While the initial URL is validated using `validate_safe_url()`, the subsequent fetch is performed using the `requests` library with redirects enabled by default. An attacker can provide a URL pointing to a malicious server that issues a 302 redirect to internal, localhost, or cloud metadata endpoints (like AWS IMDSv1). Because the redirect target is not revalidated, the application may fetch and parse sensitive internal content. This issue is fixed in version 1.1.2 by using an SSRF-safe transport that validates every request in a redirect chain.
Affected products
- LangChain langchain-text-splitters < 1.1.2
- Red Hat Migration Toolkit for Applications 8 8
- Red Hat OpenShift Lightspeed
- Red Hat Red Hat Ansible Automation Platform 2 2
- Red Hat Red Hat OpenShift AI (RHOAI)
Timeline
- 2026-04-16: advisory: GitHub advisory published by LangChain
- 2026-04-24: disclosed: CVE published to NVD
- 2026-04-24: patched: Fix released in version 1.1.2