langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

CVSS 3.1 langchain-openai View details

OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks

OpenClaw: QQBot direct media upload skipped URL SSRF validation

used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This

CVSS 3.1 langchain View details

counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input. This vulnerability is fixed

CVSS 3.7 langchain_core View details

Fickling has a detection bypass via stdlib network-protocol constructors