Server-Side Request Forgery Vulnerability in IBM Langflow OSS
CVE-2026-12765
6.5MEDIUM
What is CVE-2026-12765?
IBM Langflow OSS versions 1.0.0 through 1.10.2 are susceptible to a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to exploit the system by sending unauthorized requests, which could lead to network enumeration and potentially pave the way for further attacks. The vulnerability presents significant risks by enabling malicious actors to misuse the trusted network environment of IBM Langflow OSS. Users are strongly advised to review the advisory and apply the necessary patches.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.2