Impact
The flaw resides in IBM Langflow OSS versions 1.0.0 to 1.9.6, where the login endpoint lacks sufficient throttling or restriction on authentication attempts. An attacker can repeatedly submit credentials until successful, leading to unauthorized access to user accounts. This weakness fits CWE‑307 and directly endangers user confidentiality and system integrity.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.9.6 are vulnerable. No other vendors or product lines are affected according to the CNA data.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is considered critical. The EPSS score is not available, but the lack of a KEV listing suggests no confirmed widespread exploitation yet. Still, the straightforward remote attack path—continuous credential attempts over the public login interface—makes exploitation realistic if an attacker can reach the endpoint. Therefore, the probability of successful exploitation could be moderate to high in environments where hardened authentication controls are absent.
OpenCVE Enrichment