ZeroHour

CVE-2026-19304

large

SSRF via URL Parser Discrepancy in IBM Langflow OSS 1.0.0–1.11.2

CVSS 3.1
7.7 high
EPSS
<1%p23
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery flaw (CWE-918) caused by a discrepancy between the URL parser used to validate user-supplied URLs and the one used to fetch them. A remote attacker with valid low-privilege credentials can submit a crafted URL that bypasses validation, causing the Langflow server to issue requests on the attacker's behalf. Successful exploitation lets the attacker read sensitive information from internal services reachable by the server, such as internal APIs or metadata endpoints (high confidentiality impact, no integrity or availability impact). Any deployment of Langflow OSS 1.0.0 through 1.11.2 is affected, which given Langflow's role as a self-hosted visual builder for LLM workflows means mostly containerized or on-prem instances. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Upgrade Langflow OSS to a release newer than 1.11.2 once IBM/the Langflow project publishes the fixed version, and verify your deployed version against the affected range. Until patched, restrict outbound network access from Langflow hosts with egress filtering or network policies so internal services are unreachable, and limit accounts permitted to create or edit flows. Review Langflow server logs for unexpected outbound requests to internal endpoints, which would indicate attempted exploitation.

Affected
IBM Langflow OSS1.0.0 through 1.11.2
Estimated exposure
large≈10,000–100,000 installations, of which likely only thousands are internet-exposed — Langflow is a widely adopted open-source LLM workflow builder with a large self-hosted and containerized install base (evidenced by tens of thousands of GitHub stars and millions of Docker pulls), but no authoritative install count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

Vendors
langflow
Products
langflow
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.