Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Decoding The SVG path Element: Curve And Arc Commands

      June 23, 2025

      This week in AI dev tools: Gemini 2.5 Pro and Flash GA, GitHub Copilot Spaces, and more (June 20, 2025)

      June 20, 2025

      Gemini 2.5 Pro and Flash are generally available and Gemini 2.5 Flash-Lite preview is announced

      June 19, 2025

      CSS Cascade Layers Vs. BEM Vs. Utility Classes: Specificity Control

      June 19, 2025

      I recommend this Chromebook over many Windows laptops that cost twice as much

      June 23, 2025

      Why I recommend this flagship TCL TV over OLED models that cost more (and don’t regret it)

      June 23, 2025

      Finally, a Lenovo ThinkPad that impressed me in performance, design, and battery life

      June 23, 2025

      3 productivity gadgets I can’t work without (and why they make such a big difference)

      June 23, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      SQL Joins

      June 23, 2025
      Recent

      SQL Joins

      June 23, 2025

      Dividing Collections with Laravel’s splitIn Helper

      June 23, 2025

      PayHere for Laravel

      June 23, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Distribution Release: IPFire 2.29 Core 195

      June 23, 2025
      Recent

      Distribution Release: IPFire 2.29 Core 195

      June 23, 2025

      TeleSculptor – transforms aerial videos and images into Geospatial 3D models

      June 23, 2025

      Rilasciato IceWM 3.8: Gestore di Finestre per il Sistema X

      June 23, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-2828 – Apache Langchain SSRF

    CVE-2025-2828 – Apache Langchain SSRF

    June 23, 2025

    CVE ID : CVE-2025-2828

    Published : June 23, 2025, 9:15 p.m. | 1 hour, 29 minutes ago

    Description : A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit does not enforce restrictions on requests to remote internet addresses, allowing it to also access local addresses. As a result, an attacker could exploit this flaw to perform port scans, access local services, retrieve instance metadata from cloud environments (e.g., Azure, AWS), and interact with servers on the local network. This issue has been fixed in version 0.0.28.

    Severity: 8.4 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-52562 – Performave Convoy Directory Traversal Vulnerability
    Next Article CVE-2025-6547 – Apache PBKDF2 Signature Spoofing Vulnerability

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2023-47029 – NCR Terminal Handler Remote Code Execution and Information Disclosure

    June 23, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-49126 – Visionatrix ComfyUI Reflected Cross-Site Scripting Vulnerability

    June 23, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    How to Use AI to Enhance Your WordPress Blog

    Learning Resources

    CVSS 10.0 Vulnerability Found in Ubiquity UniFi Protect Cameras

    Development

    CVE-2025-37812 – Linux Kernel USB cdns3 NCM Gadget Deadlock

    Common Vulnerabilities and Exposures (CVEs)

    LACT configures and monitors AMD, NVIDIA and Intel GPUs

    Linux

    Highlights

    CVE-2025-43008 – Microsoft SharePoint Information Disclosure Vulnerability

    May 13, 2025

    CVE ID : CVE-2025-43008

    Published : May 13, 2025, 1:15 a.m. | 1 hour, 49 minutes ago

    Description : Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

    Severity: 5.8 | MEDIUM

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    CVE-2025-5973 – PHPGurukul Restaurant Table Booking System Cross Site Scripting Vulnerability

    June 10, 2025

    Two Mirai Botnets, Lzrd and Resgod Spotted Exploiting Wazuh Flaw

    June 10, 2025

    CVE-2025-4177 – Flynax Bridge – Unauthenticated User Deletion Vulnerability

    May 2, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.