langchain-text-splitters vulnerabilities
CVEs whose affected-version data names the langchain-text-splitters package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-41481Medium· 6.5LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
▾ Sunlitlangchain-text-splitters · langchain-text-splittersEPSS 0.26%via OSV
CVE-2025-6985High· 7.5LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
▾ Twilightlangchain-text-splitters · langchain-text-splittersEPSS 0.51%via OSV