CVE-2026-41481: LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using val...

Added to the CISA Known Exploited Vulnerabilities catalog on 24 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the defaul...

Required action: Review and patch if applicable to your AI infrastructure.