Description
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery that permits an attacker who is authenticated to the IBM Langflow OSS application to cause the system to send arbitrary HTTP requests on the attacker’s behalf. This functionality can be leveraged for network reconnaissance, access to internal services, or other downstream exploits. The flaw is a classic SSRF weakness as noted by CWE‑918 and may lead to compromise if internal resources are accessed.

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.11.1 are impacted. These include the releases listed in the known CPEs for 1.0.0 and 1.11.1. The latest disclosed fix is in version 1.11.2 released on PyPI.

Risk and Exploitability

The CVSS score of 4.3 indicates a low‑to‑moderate severity. EPSS data are not available, and the issue is not yet cataloged in CISA’s KEV. Exploitation requires the attacker to be authenticated to the application, after which they can craft malicious request targets. The primary threat is the ability to perform internal network enumeration or further pivot attacks through outbound requests from the host.

Generated by OpenCVE AI on August 29, 2026 at 00:05 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade Langflow OSS to version 1.11.2 from the PyPI repository
  • Restrict outbound traffic from the Langflow OSS instance to only necessary destinations to limit SSRF impact
  • Monitor outbound network activity for suspicious requests originating from Langflow OSS

Generated by OpenCVE AI on August 29, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Title Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:49:25.781Z

Reserved: 2026-07-31T21:21:10.287Z

Link: CVE-2026-18545

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.743

Modified: 2026-08-28T22:16:46.743

Link: CVE-2026-18545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T01:00:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)