StackRadar

CVE-2026-41488

Low

Advisory

Published 16 Apr 2026In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
langchain-openaipypi0.0.5, 0.1.7, 0.1.17, 0.2.0+4 more1.1.148
OSV records
GHSA-r7w7-9xr2-qq2r
Also known as
PYSEC-2026-76

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
langchain-openai@0.0.5
1.1.14

Open the chart page →

11,205
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
langchain-openai@0.2.14
1.1.14

Open the chart page →

12,907
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
langchain-openai@0.1.17
1.1.14

Open the chart page →

4,042
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
langchain-openai@0.3.23
1.1.14

Open the chart page →

58,897
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
langchain-openai@1.1.0
1.1.14

Open the chart page →

2,736
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
langchain-openai@0.1.7
1.1.14

Open the chart page →

18,922
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
langchain-openai@0.3.8
1.1.14

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
langchain-openai@0.3.8
1.1.14

Open the chart page →

4,718
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-41488.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
langchain-openai@0.2.0
1.1.14

Open the chart page →

28,858

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
langchain-openai@0.3.8
1.1.14
2
ilum/streamlit-example:1.0.0ce5dcdeb22ba
langchain-openai@1.1.0
1.1.14
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
langchain-openai@0.2.0
1.1.14
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
langchain-openai@0.3.23
1.1.14
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
langchain-openai@0.2.14
1.1.14
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
langchain-openai@0.0.5
1.1.14
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
langchain-openai@0.1.17
1.1.14
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
langchain-openai@0.1.7
1.1.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.