{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41481.json"
      }
    ],
    "title": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass",
    "tracking": {
      "current_release_date": "2026-06-30T03:56:15+00:00",
      "generator": {
        "date": "2026-06-30T03:56:15+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-41481",
      "initial_release_date": "2026-04-24T20:54:27.713000+00:00",
      "revision_history": [
        {
          "date": "2026-04-24T20:54:27.713000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-28T08:48:25.459580+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:56:15+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Migration Toolkit for Applications 8",
                "product": {
                  "name": "Migration Toolkit for Applications 8",
                  "product_id": "migration_toolkit_for_applications_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:migration_toolkit_applications:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Migration Toolkit for Applications 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "OpenShift Lightspeed",
                "product": {
                  "name": "OpenShift Lightspeed",
                  "product_id": "openshift_lightspeed",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_lightspeed"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "OpenShift Lightspeed"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2",
                  "product_id": "red_hat_ansible_automation_platform_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform 2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "mta/mta-solution-server-rhel9",
            "product": {
              "name": "mta/mta-solution-server-rhel9",
              "product_id": "mta/mta-solution-server-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/mta-solution-server-rhel9?repository_url=registry.redhat.io/mta/mta-solution-server-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift-lightspeed/lightspeed-service-api-rhel9",
            "product": {
              "name": "openshift-lightspeed/lightspeed-service-api-rhel9",
              "product_id": "openshift-lightspeed/lightspeed-service-api-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-service-api-rhel9?repository_url=registry.redhat.io/openshift-lightspeed/lightspeed-service-api-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-24/lightspeed-rhel8",
            "product": {
              "name": "ansible-automation-platform-24/lightspeed-rhel8",
              "product_id": "ansible-automation-platform-24/lightspeed-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-rhel8?repository_url=registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
            "product": {
              "name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
              "product_id": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel8?repository_url=registry.redhat.io/ansible-automation-platform-25/lightspeed-chatbot-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-25/lightspeed-rhel8",
            "product": {
              "name": "ansible-automation-platform-25/lightspeed-rhel8",
              "product_id": "ansible-automation-platform-25/lightspeed-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-rhel8?repository_url=registry.redhat.io/ansible-automation-platform-25/lightspeed-rhel8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-llama-stack-core-rhel9",
            "product": {
              "name": "rhoai/odh-llama-stack-core-rhel9",
              "product_id": "rhoai/odh-llama-stack-core-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-llama-stack-core-rhel9?repository_url=registry.redhat.io/rhoai/odh-llama-stack-core-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
            "product": {
              "name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
              "product_id": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-trustyai-nemo-guardrails-server-rhel9?repository_url=registry.redhat.io/rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mta/mta-solution-server-rhel9 as a component of Migration Toolkit for Applications 8",
          "product_id": "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9"
        },
        "product_reference": "mta/mta-solution-server-rhel9",
        "relates_to_product_reference": "migration_toolkit_for_applications_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed",
          "product_id": "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9"
        },
        "product_reference": "openshift-lightspeed/lightspeed-service-api-rhel9",
        "relates_to_product_reference": "openshift_lightspeed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-24/lightspeed-rhel8 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8"
        },
        "product_reference": "ansible-automation-platform-24/lightspeed-rhel8",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8"
        },
        "product_reference": "ansible-automation-platform-25/lightspeed-chatbot-rhel8",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-25/lightspeed-rhel8 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8"
        },
        "product_reference": "ansible-automation-platform-25/lightspeed-rhel8",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
        },
        "product_reference": "rhoai/odh-llama-stack-core-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
        },
        "product_reference": "rhoai/odh-trustyai-nemo-guardrails-server-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-41481",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "discovery_date": "2026-04-24T22:00:57.208355+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2461733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in LangChain and langchain-text-splitters. This vulnerability, a Server-Side Request Forgery (SSRF) bypass, allows a remote attacker to redirect a seemingly safe URL to internal network resources. By exploiting unvalidated redirects, an attacker could access sensitive data from internal, localhost, or cloud metadata endpoints. This could result in information disclosure or data exfiltration if the application processes and exposes the content from these redirected requests.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important information disclosure flaw in LangChain and langchain-text-splitters, affecting Red Hat products that process URLs using these components. The vulnerability allows a Server-Side Request Forgery (SSRF) redirect bypass, where initial URL validation is circumvented by unvalidated redirect targets. This could enable an attacker to access internal network resources and potentially exfiltrate sensitive data if the application exposes the content from these redirected requests.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9",
          "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-41481"
        },
        {
          "category": "external",
          "summary": "RHBZ#2461733",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461733"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-41481",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-41481"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-41481",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41481"
        },
        {
          "category": "external",
          "summary": "https://github.com/langchain-ai/langchain/security/advisories/GHSA-fv5p-p927-qmxr",
          "url": "https://github.com/langchain-ai/langchain/security/advisories/GHSA-fv5p-p927-qmxr"
        }
      ],
      "release_date": "2026-04-24T20:54:27.713000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "To mitigate this issue, Red Hat customers should ensure that applications utilizing LangChain's HTMLHeaderTextSplitter.split_text_from_url() function do not process untrusted or unvalidated URLs. Implement strict input validation for all URL inputs to prevent redirection to internal network resources. If an application exposes the content of processed Document objects to external requesters, consider reconfiguring the application to restrict such exposure.",
          "product_ids": [
            "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9",
            "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9",
            "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9",
            "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "migration_toolkit_for_applications_8:mta/mta-solution-server-rhel9",
            "openshift_lightspeed:openshift-lightspeed/lightspeed-service-api-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-chatbot-rhel8",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-nemo-guardrails-server-rhel9"
          ]
        }
      ],
      "title": "langchain-text-splitters: LangChain: Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass"
    }
  ]
}