Description
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
Published: 2026-09-04
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server‑Side Request Forgery
Action: Patch Now
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server‑side request forgery flaw that permits a remote attacker to provide malformed or intentionally crafted URLs, which the application forwards without proper validation, enabling the attacker to access internal resources and retrieve sensitive information.

Affected Systems

The affected product is IBM Langflow OSS. Versions from 1.0.0 up to and including 1.11.2 are susceptible, as indicated by the documented CPE strings and the vendor's advisory.

Risk and Exploitability

The flaw carries a CVSS score of 8.6, indicating a high potential impact. The EPSS score is not provided, so the likelihood of exploitation remains uncertain, and the vulnerability is not listed in CISA's KEV catalog. Attackers can trigger the SSRF by supplying malicious URLs via any input channel that the application accepts; no explicit prerequisite such as local privileges is mentioned in the advisory, making it inferred that the attack can be performed by any entity with access to the relevant interface, an assumption made based on typical SSRF patterns.

Generated by OpenCVE AI on September 4, 2026 at 17:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Apply the IBM Langflow OSS 1.11.3 release, which removes the CWE‑918 SSRF flaw.
  • If upgrading immediately is not possible, enforce strict outbound network controls or firewall rules that block requests to internal or sensitive IP ranges.
  • Continuously monitor outbound traffic for anomalous requests that may indicate exploitation attempts.

Generated by OpenCVE AI on September 4, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
Title Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Apple Macos
Ibm Langflow Oss
Langflow Langflow
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T15:46:36.305Z

Reserved: 2026-08-07T17:29:08.674Z

Link: CVE-2026-19305

cve-icon Vulnrichment

Updated: 2026-09-04T15:46:32.476Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:24.323

Modified: 2026-09-08T22:06:27.903

Link: CVE-2026-19305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)