CVE-2026-19305
largeUnauthenticated SSRF in IBM Langflow OSS 1.0–1.11.2
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery flaw (CWE-918) that allows a remote attacker to make the Langflow server issue requests to attacker-chosen or internal network endpoints. Because the issue requires no privileges or user interaction and is reachable over the network, an unauthenticated attacker who can reach a vulnerable instance can potentially read responses from internal services, APIs, or cloud instance-metadata endpoints. The attacker gains access to sensitive information (high confidentiality impact) but the flaw does not affect integrity or availability. Any deployment running Langflow OSS 1.0.0 through 1.11.2 is affected, with internet-exposed instances at greatest risk. No public proof of concept, known in-the-wild exploitation, or KEV listing exists; EPSS puts the 30-day exploitation probability at just 0.3%.
What to do: Upgrade Langflow OSS to a fixed release beyond 1.11.2 per IBM's advisory (a fixed version number was not specified in the available data). Until patched, restrict network access to Langflow servers, avoid exposing them directly to the internet, and apply egress filtering so the host cannot reach cloud metadata endpoints (e.g., 169.254.169.254) or sensitive internal services. Audit logs and configurations for signs of unexpected outbound requests from Langflow instances.
| IBM Langflow OSS | 1.0.0 through 1.11.2 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.