Server-Side Request Forgery Vulnerability in IBM Langflow OSS
CVE-2026-12767
6.5MEDIUM
What is CVE-2026-12767?
IBM Langflow OSS versions 1.0.0 through 1.11.5 expose a server-side request forgery (SSRF) vulnerability. This flaw permits an unauthenticated attacker to send unauthorized requests from the IBM Langflow system. As a result, the attacker could potentially enumerate network resources and facilitate various types of attacks, posing significant risks to the security of the underlying infrastructure.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.5