Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw that allows a remote authenticated attacker to trigger an uncontrolled resource consumption during ZIP file extraction, leading to a disruption of service. The weakness is classified as CWE‑400, indicating an input/control validation error that can exhaust system resources. When exploited, the server may become unresponsive or terminate, impacting the availability of the application for legitimate users.

Affected Systems

The affected product is IBM Langflow OSS. Versions 1.0.0 up to and including 1.12.2 are vulnerable. The vendor recommends upgrading to 1.12.3, which contains the fix.

Risk and Exploitability

The CVSS score of 4.3 reflects a moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The attack requires remote authenticated access; an attacker with valid credentials can trigger the denial of service by uploading a crafted ZIP file. The exploitability is therefore limited by the need for authentication but can be readily executed by any user with access to the system.

Generated by OpenCVE AI on October 7, 2026 at 01:36 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBMLangflow OSS to version 1.12.3 to apply the vendor‑supplied fix for the ZIP extraction overflow.
  • If immediate upgrade is not possible, restrict the size of ZIP files accepted by the application or remove the ability to unzip user‑provided archives entirely until a patch can be applied.
  • Limit the resources (CPU, memory) allocated to the extraction process via container or host‑level controls to reduce the impact of any future uncontrolled consumption.

Generated by OpenCVE AI on October 7, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:00:53.149Z

Reserved: 2026-09-18T13:55:19.829Z

Link: CVE-2026-93679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:35.710

Modified: 2026-10-07T01:16:35.710

Link: CVE-2026-93679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption