ZeroHour

CVE-2026-19305

large

Unauthenticated SSRF in IBM Langflow OSS 1.0–1.11.2

CVSS 3.1
7.5 high
EPSS
<1%p21
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server-side request forgery flaw (CWE-918) that allows a remote attacker to make the Langflow server issue requests to attacker-chosen or internal network endpoints. Because the issue requires no privileges or user interaction and is reachable over the network, an unauthenticated attacker who can reach a vulnerable instance can potentially read responses from internal services, APIs, or cloud instance-metadata endpoints. The attacker gains access to sensitive information (high confidentiality impact) but the flaw does not affect integrity or availability. Any deployment running Langflow OSS 1.0.0 through 1.11.2 is affected, with internet-exposed instances at greatest risk. No public proof of concept, known in-the-wild exploitation, or KEV listing exists; EPSS puts the 30-day exploitation probability at just 0.3%.

What to do: Upgrade Langflow OSS to a fixed release beyond 1.11.2 per IBM's advisory (a fixed version number was not specified in the available data). Until patched, restrict network access to Langflow servers, avoid exposing them directly to the internet, and apply egress filtering so the host cannot reach cloud metadata endpoints (e.g., 169.254.169.254) or sensitive internal services. Audit logs and configurations for signs of unexpected outbound requests from Langflow instances.

Affected
IBM Langflow OSS1.0.0 through 1.11.2 (inclusive)
Estimated exposure
large≈tens of thousands of internet-exposed instances (public scans during the 2025 Langflow RCE episode found roughly 30,000–50,000 reachable servers) — Internet-wide scans during the May 2025 Langflow exploitation wave identified on the order of 30,000–50,000 publicly reachable Langflow instances, and this SSRF's affected range spans essentially all 1.x releases, so a similar or larger…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

Vendors
langflow
Products
langflow
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.