URL Parsing Discrepancy in IBM Langflow OSS Affects Sensitive Information Access
CVE-2026-19304
7.7HIGH
What is CVE-2026-19304?
A vulnerability exists in IBM Langflow OSS from versions 1.0.0 to 1.11.2, where a remote authenticated attacker could exploit a URL parser discrepancy. This flaw allows unauthorized access to sensitive information from internal services, potentially leading to data compromise and breach of privacy.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.2