Skip to content

fix: constrain langsmith >=0.6.3 on Python >=3.10 to resolve CVE-2026-25528 - #25

Merged
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/security-alerts-langsmith-2026-02-24
Feb 25, 2026
Merged

John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/security-alerts-langsmith-2026-02-24

Conversation

@jkennedyvz

Copy link
Copy Markdown
Contributor

Security Alert Patch — medium severity

Resolves CVE-2026-25528 for Python >= 3.10 environments.

Package Updated

Package Constraint Python Strategy CVE
langsmith >=0.6.3 >=3.10 Constraint (C) CVE-2026-25528 (medium)
langsmith >=0.3.45 <3.10 Passthrough n/a

CVE Details

CVE-2026-25528 (medium) — langsmith >= 0.4.10, < 0.6.3: SSRF via crafted X-Forwarded-For / tracing headers in the LangSmith Client SDK.

Python 3.9 limitation

langsmith >= 0.6.3 requires Python >= 3.10. There is no patched release compatible with Python 3.9. The constraint is therefore split:

  • Python >= 3.10: resolves langsmith 0.7.6 ✓ patched
  • Python 3.9: resolves langsmith 0.4.37 — still vulnerable; no upstream fix available

This constraint can be removed once langchain-core updates its own langsmith lower bound to >= 0.6.3.

Skipped (no patched version available)

  • docarray CVE-2025-5150 (medium) — no first_patched_version
  • orjson CVE-2025-67221 (medium) — no first_patched_version
  • langchain-core CVE-2026-26013 (low) — requires bumping to >= 1.2.11 (past langchain-openai ^0.3 compatibility boundary); warrants a separate ecosystem upgrade PR

Verification

  • Lockfile regenerated (poetry lock)
  • Linters pass (ruff check, ruff format --check)

🤖 Submitted by langster-patch

…-25528

langsmith >= 0.4.10, < 0.6.3 is vulnerable to SSRF via crafted tracing
headers. langsmith >= 0.6.3 requires Python >= 3.10, so the constraint
is split: >= 0.6.3 for Python >= 3.10, >= 0.3.45 for Python 3.9 (no
patched release available for 3.9 upstream). Python >= 3.10 now resolves
langsmith 0.7.6. Strategy C constraint; remove once langchain-core
pulls in langsmith >= 0.6.3 directly.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@jkennedyvz
John Kennedy (jkennedyvz) merged commit be6ba65 into main Feb 25, 2026
17 checks passed
@jkennedyvz
John Kennedy (jkennedyvz) deleted the fix/security-alerts-langsmith-2026-02-24 branch February 25, 2026 02:52
John Kennedy (jkennedyvz) added a commit that referenced this pull request Mar 1, 2026
## Summary

Python 3.9 reached end-of-life on 2025-10-05. This PR removes it from
the supported range.

## Changes

- `pyproject.toml`: `python = ">=3.9,<4.0"` → `">=3.10,<4.0"`
- `poetry.lock`: regenerated — 32 fewer lines as 3.9-only resolution
paths are removed

## Notes

- The CI matrix (`_test.yml`, `_lint.yml`,
`_compile_integration_test.yml`, `_scheduled_test.yml`) already starts
at 3.10 — no workflow changes needed.
- Dropping 3.9 also unblocks a clean `langsmith >= 0.6.3` constraint
(see PR #25, CVE-2026-25528) — that PR's split constraint for Python
3.9/3.10 can be simplified to an unconditional `>= 0.6.3` once this
merges.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant