Description
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
Published: 2026-09-04
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch Now
AI Analysis

Impact

IBM Langflow OSS implements URL handling in several components without robust validation, creating a server‑side request forgery (SSRF) weakness identified as CWE‑918. By crafting requests that include arbitrary URLs, a remote authenticated attacker can instruct the application to contact internal or privileged services and retrieve sensitive information, potentially compromising confidentiality and integrity within the infrastructure. Based on the description, it is inferred that the vulnerability allows the attacker to direct the Langflow process to fetch arbitrary resources from a wide range of internal or external targets.

Affected Systems

The flaw exists in IBM Langflow OSS releases from version 1.0.0 up to 1.11.2. IBM strongly recommends upgrading to 1.11.3 to remediate the issue. No other vendors or product lines are currently reported to be affected.

Risk and Exploitability

The CVSS score of 5 denotes a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the application; the attack surface resides in the broker or API endpoints that forward user‑supplied URLs. Based on the description, it is inferred that no confirmed exploitation has been publicly reported, so the likelihood remains theoretical until an exploit is demonstrated.

Generated by OpenCVE AI on September 4, 2026 at 19:12 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.3 immediately.
  • If an upgrade cannot be performed right away, restrict outbound network traffic from the Langflow process to only approved and trusted hosts or IP ranges using firewall rules or network segmentation.
  • Disable or limit the components that accept user‑supplied URLs from executing external requests until a patch can be applied.

Generated by OpenCVE AI on September 4, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
Title Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Apple Macos
Ibm Langflow Oss
Langflow Langflow
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:29:14.728Z

Reserved: 2026-08-07T17:22:06.565Z

Link: CVE-2026-19301

cve-icon Vulnrichment

Updated: 2026-09-04T17:29:10.861Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:22.650

Modified: 2026-09-08T22:16:54.000

Link: CVE-2026-19301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)