{"id":"ECHO-8479-4c4c-18a0","modified":"2026-09-15T03:33:31.381645475Z","published":"2026-07-01T13:02:23.107Z","upstream":["CVE-2026-40087","GHSA-926x-3r5x-gfhw"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-40087"},{"type":"WEB","url":"https://github.com/advisories/GHSA-926x-3r5x-gfhw"}],"affected":[{"package":{"name":"langchain-core","ecosystem":"Echo:PyPI","purl":"pkg:pypi/langchain-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.21+echo.2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-8479-4c4c-18a0.json"}}],"schema_version":"1.9.0"}