ADVISORY UNAUTH-2026-0022
TYPE exposure-class
PRODUCT LangServe
SEVERITY CRITICAL
LangServe chain API exposed without authentication
published 2026-08-05 · updated 2026-08-05
Why it matters
LangServe publishes your LangChain/LangGraph runnable over HTTP with a playground UI. Without auth, anyone can open /playground or call /invoke and run your chain against your models, tools, and data.
What a probe sees
GET /openapi.json lists LangServe /invoke + /playground/ paths without auth.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
no-auth-by-design
In the wild
No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.
Fix it
References
Cite this record
unauth.dev advisory UNAUTH-2026-0022 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0022. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.