Denial of Service Vulnerability in IBM Langflow OSS Software
CVE-2026-7528
7.1HIGH
What is CVE-2026-7528?
The denial of service vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.0 can lead to uncontrolled resource consumption, which may cause significant disruption to service. This flaw allows attackers to exploit system resources, potentially leading to system outages and hindering legitimate user access. Organizations utilizing these versions are urged to implement remediation measures promptly. Refer to IBM's advisory for patch details and further guidance.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.9.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was reported to IBM by Ori Lahav (Rubrik Inc.) orilahav@tauex.tau.ac.il.