Description
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
Published: 2026-09-04
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery (SSRF)
Action: Upgrade
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.2 contain a server-side request forgery flaw caused by missing URL validation in flow components. A remote authenticated attacker can supply arbitrary URLs to the flow when executing a request, causing the application to perform HTTP requests to internal or external resources. The attacker could potentially read or download sensitive files, exfiltrate data, or use the application as a pivot to reach other internal network services, compromising confidentiality and integrity of data within the environment.

Affected Systems

The affected product is IBM Langflow OSS. The vulnerable releases span from version 1.0.0 up to and including 1.10.2. Any deployment running these versions is potentially impacted.

Risk and Exploitability

The CVSS score for this vulnerability is 5, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through an authenticated API request to the vulnerable flow components; the attacker needs valid credentials to trigger the SSRF. No public exploit is known, but the moderate score reflects the potential for significant information disclosure if exploited.

Generated by OpenCVE AI on September 4, 2026 at 18:29 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade Langflow OSS to 1.10.3 or later as recommended by IBM.
  • Restrict access to flow components to only authorized users or roles, limiting potential exploitation.
  • If upgrade is delayed, isolate the application from internal network resources by configuring outbound network restrictions or firewall rules to block unauthorized internal requests.

Generated by OpenCVE AI on September 4, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
Title Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Apple Macos
Ibm Langflow Oss
Langflow Langflow
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:25:26.383Z

Reserved: 2026-07-27T21:14:30.237Z

Link: CVE-2026-17631

cve-icon Vulnrichment

Updated: 2026-09-08T17:24:25.326Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:55.507

Modified: 2026-09-09T15:01:37.170

Link: CVE-2026-17631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T20:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)