Server-Side Request Forgery (SSRF) in LangChain - CVE-2026-26013
Published: April 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to server-side request forgery (ssrf) in ChatOpenAI.get_num_tokens_from_messages() when processing messages containing user-supplied image_url values for token counting. A remote attacker can supply a crafted image URL to cause a denial of service.
The issue is blind SSRF, and token counting may occur outside of model invocation such as in logging, metrics, or token budgeting flows.
Affected software
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Maximo Application Suite Ai Service
How to mitigate CVE-2026-26013
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
Maximo Application Suite Ai Service - update to 9.1.16