{"data":{"ecosystem":"pypi","name":"langchain-openai","url":"https://aisecwatch.com/packages/pypi/langchain-openai","latestVersion":"1.7.0","firstReleaseAt":"2024-01-05T23:12:54.088Z","repository":"https://github.com/langchain-ai/langchain","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-01-05T23:12:54.088Z","integratedVersion":"0.0.1rc0","sdks":["langchain"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:aiohttp"]},"dependencies":[{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2.0.0,>=1.6.8","scope":"runtime"},{"ecosystem":"pypi","name":"openai","versionSpec":"<4.0.0,>=2.45.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4.0.0,>=3.11.0","scope":"extra:azure-identity"},{"ecosystem":"pypi","name":"azure-identity","versionSpec":"<2.0.0,>=1.25.0","scope":"extra:azure-identity"},{"ecosystem":"pypi","name":"certifi","versionSpec":">=2024.6.2","scope":"runtime"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":"<1.0.0,>=0.7.0","scope":"runtime"}],"advisories":[{"id":"20412666-d06f-4060-80e4-9ac1e072ff55","url":"https://aisecwatch.com/issues/20412666-d06f-4060-80e4-9ac1e072ff55","cveId":"CVE-2026-41488","title":"CVE-2026-41488: LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's…","headline":"LangChain OpenAI SSRF bypass via DNS rebinding in image token counting","severity":"low","publishedAt":"2026-04-24T21:16:19.637Z","affected":["langchain-openai@< 1.1.14 (fixed: 1.1.14)"],"epssScore":0.00239,"matchedBy":"ecosystem"},{"id":"63f6c3cb-dd25-48d8-b025-5ae867be432d","url":"https://aisecwatch.com/issues/63f6c3cb-dd25-48d8-b025-5ae867be432d","cveId":null,"title":"GHSA-r7w7-9xr2-qq2r: langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding","headline":null,"severity":"low","publishedAt":"2026-04-16T23:00:12.000Z","affected":["langchain-openai@< 1.1.14 (fixed: 1.1.14)"],"epssScore":null,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:50:50.562Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}