Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw that allows a remote authenticated attacker to trigger an uncontrolled resource consumption during ZIP file extraction, leading to a disruption of service. The weakness is classified as CWE‑400, indicating an input/control validation error that can exhaust system resources. When exploited, the server may become unresponsive or terminate, impacting the availability of the application for legitimate users.
Affected Systems
The affected product is IBM Langflow OSS. Versions 1.0.0 up to and including 1.12.2 are vulnerable. The vendor recommends upgrading to 1.12.3, which contains the fix.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The attack requires remote authenticated access; an attacker with valid credentials can trigger the denial of service by uploading a crafted ZIP file. The exploitability is therefore limited by the need for authentication but can be readily executed by any user with access to the system.
OpenCVE Enrichment