Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery allowing internal data disclosure
Action: Immediate patch
AI Analysis

Impact

Missing URL validation on server‑side URL fetches in IBM Langflow OSS creates a classic SSRF flaw that permits a remote attacker to supply arbitrary URLs and cause the application to reach internal network resources. The attacker can exfiltrate sensitive data from the internal environment, such as database endpoints, configuration files or other services accessible only from within the network. This weakness is directly identified as CWE‑918 and can result in confidentiality compromise at the application or infrastructure level.

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.11.5 are vulnerable because they lack the required egress validation. Version 1.11.6 incorporates the fix and should be deployed to any installations remaining on older releases.

Risk and Exploitability

The issue carries a CVSS score of 8.6, indicating high severity, and is not listed in the CISA KEV catalogue. The EPSS score is not available, but the lack of input validation suggests a straightforward attack path: a remote attacker crafts a request with a malicious URL and sends it to the vulnerable endpoint, causing the server to make an unexpected internal network call. Exploitation requires no special privileges on the target system.

Generated by OpenCVE AI on September 11, 2026 at 04:28 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.6 or later to apply the vendor patch.
  • If an upgrade cannot be performed immediately, block the application’s outbound traffic to internal IP ranges or enforce a whitelist of allowed external domains for URL fetches.
  • Segment the network so that the application resides in a separate subnet from sensitive internal services, limiting the impact of any SSRF exploitation.

Generated by OpenCVE AI on September 11, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
Title Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T20:31:55.931Z

Reserved: 2026-08-26T17:04:56.688Z

Link: CVE-2026-81213

cve-icon Vulnrichment

Updated: 2026-09-11T18:48:09.002Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:02.110

Modified: 2026-09-16T00:56:23.740

Link: CVE-2026-81213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)