Server-Side Request Forgery in IBM Langflow OSS Affects Data Security
CVE-2026-19305

8.6HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-19305?

IBM Langflow OSS, specifically versions 1.0.0 to 1.11.2, is vulnerable to a server-side request forgery (SSRF) attack. This vulnerability can allow a remote attacker to exploit the system and potentially gain access to sensitive data. Effective security measures should be implemented to mitigate this risk.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.11.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.