CVE-2026-19304
largeSSRF via URL Parser Discrepancy in IBM Langflow OSS 1.0.0–1.11.2
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery flaw (CWE-918) caused by a discrepancy between the URL parser used to validate user-supplied URLs and the one used to fetch them. A remote attacker with valid low-privilege credentials can submit a crafted URL that bypasses validation, causing the Langflow server to issue requests on the attacker's behalf. Successful exploitation lets the attacker read sensitive information from internal services reachable by the server, such as internal APIs or metadata endpoints (high confidentiality impact, no integrity or availability impact). Any deployment of Langflow OSS 1.0.0 through 1.11.2 is affected, which given Langflow's role as a self-hosted visual builder for LLM workflows means mostly containerized or on-prem instances. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.
What to do: Upgrade Langflow OSS to a release newer than 1.11.2 once IBM/the Langflow project publishes the fixed version, and verify your deployed version against the affected range. Until patched, restrict outbound network access from Langflow hosts with egress filtering or network policies so internal services are unreachable, and limit accounts permitted to create or edit flows. Review Langflow server logs for unexpected outbound requests to internal endpoints, which would indicate attempted exploitation.
| IBM Langflow OSS | 1.0.0 through 1.11.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.