langchain-exa
The agent engineering platform.
Activity
- Latest release
- 5mo ago
- Total releases
- 9
- Cadence
- ~4 months
- Last 12 months
- 3
Reach
- Stars
- 146.2k
Details
- License
- MIT
- First release
- Jan 25, 2024
| Version | Released | |
|---|---|---|
1.1.0
minor
| ||
1.0.0
major
| ||
1.0.0a1
pre
| ||
0.3.1
patch
1 CVE
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev | ||
0.1.0
minor
1 CVE
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev | ||
0.0.1
initial
2 CVEs
CVE-2024-58340
PYSEC-2026-75
Jan 12, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when extracting tool actions from model output. An attacker who can supply or influence the parsed text (for example via prompt injection in downstream applications that pass LLM output directly into MRKLOutputParser.parse()) can trigger excessive CPU consumption by providing a crafted payload, causing significant parsing delays and a denial-of-service condition. Affected versions
0.0.1
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
Fixed in
1.0.0a1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2024-0243
PYSEC-2024-235
GHSA-h9j7-5xvc-qhg5
PYSEC-2026-1509
Feb 26, 2024
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
With the following crawler configuration:
An attacker in control of the contents of https://github.com/langchain-ai/langchain/blob/bf0b3cc0b5ade1fb95a5b1b6fa260e99064c2e22/libs/community/langchain_community/document_loaders/recursive_url_loader.py#L51-L51 Resolved in https://github.com/langchain-ai/langchain/pull/15559 Affected versions
0.0.1
Fixed in
0.1.0
References Updated Jul 07, 2026 · Source: OSV.dev |