Denial of Service Vulnerability in Langflow Tool by Langflow AI
CVE-2026-55446

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-55446?

The Langflow tool, designed for creating AI-driven agents and workflows, is susceptible to a Denial of Service attack in versions prior to 1.0.19. An attacker can exploit this vulnerability by sending unauthenticated requests to the /api/v1/files/upload/ endpoint. By utilizing an excessively long multipart form boundary, this can render the Langflow application inoperative for all legitimate users indefinitely. The issue has been addressed in version 1.0.19, promoting improved security and service reliability.

Affected Version(s)

langflow < 1.0.19

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.