<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:33:26.679158+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321987</id>
    <title>EUVD-2026-321987</title>
    <updated>2026-10-02T11:33:27.067759+00:00</updated>
    <content>EUVD-2026-321987</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44843</id>
    <title>fkie_cve-2026-44843</title>
    <updated>2026-10-02T11:33:27.067829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments. This vulnerability is fixed in 0.3.85 and 1.3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44843"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pjwx-r37v-7724</id>
    <title>GHSA-pjwx-r37v-7724 — LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists</title>
    <updated>2026-10-02T11:33:27.067871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langchain-core</p>
<p>LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call `load()` with `allowed_objects="all"`. This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments.</p>
<p>Applications are exposed only when all of the following are true:</p>
<p>1. The application accepts untrusted structured input, such as JSON, from a user or network request.
2. The application does not validate or canonicalize that input into an inert schema before invoking LangChain.
3. Attacker-controlled nested dictionaries or lists are preserved in LangChain run inputs or outputs.
4. The application uses an affected API path that later deserializes that run data.</p>
<p>Known affected runtime surfaces include:</p>
<p>- `RunnableWithMessageHistory`
- `astream_log()`
- `astream_events(version="v1")`</p>
<p>Related unsafe deserialization patterns may also affect applications that explicitly load serialized LangChain prompt or runnable objects from untrusted sources, including shared prompt stores, Hub artifacts with model configuration, or other application-controlled serialization stores.</p>
<p>Applications that validate incomin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pjwx-r37v-7724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2564</id>
    <title>PYSEC-2026-2564 — LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists</title>
    <updated>2026-10-02T11:33:27.067931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langchain-core</p>
<p>LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call `load()` with `allowed_objects="all"`. This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments.</p>
<p>Applications are exposed only when all of the following are true:</p>
<p>1. The application accepts untrusted structured input, such as JSON, from a user or network request.
2. The application does not validate or canonicalize that input into an inert schema before invoking LangChain.
3. Attacker-controlled nested dictionaries or lists are preserved in LangChain run inputs or outputs.
4. The application uses an affected API path that later deserializes that run data.</p>
<p>Known affected runtime surfaces include:</p>
<p>- `RunnableWithMessageHistory`
- `astream_log()`
- `astream_events(version="v1")`</p>
<p>Related unsafe deserialization patterns may also affect applications that explicitly load serialized LangChain prompt or runnable objects from untrusted sources, including shared prompt stores, Hub artifacts with model configuration, or other application-controlled serialization stores.</p>
<p>Applications that validate incomin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:43038</id>
    <title>RHSA-2026:43038 — Red Hat Security Advisory: Migration Toolkit for Applications</title>
    <updated>2026-10-02T11:33:27.067981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: URI authority bypass due to improper delimiter handling fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following mistune: Mistune: Regular Expression Denial of Service (ReDoS) via crafted Markdown input net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() jupyter-server: Jupyter Server: Unauthorized File Access via Path Traversal Vulnerability net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing jupyter-server: Jupyter Server: Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list net/mail: golang: net/mail…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:43038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1447</id>
    <title>WID-SEC-W-2026-1447 — LangChain: Schwachstelle ermöglicht Manipulation von Dateien und Offenlegung von Informationen</title>
    <updated>2026-10-02T11:33:27.068055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LangChain ausnutzen, um Dateien zu manipulieren, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1447"/>
  </entry>
</feed>
