Cryptographic Weakness in IBM Langflow OSS Affecting Encryption Keys
CVE-2026-8470

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-8470?

IBM Langflow OSS versions 1.0.0 through 1.10.3 employ a non-cryptographic random module for generating Fernet encryption keys from user secrets that are shorter than 32 characters. This reliance on the deterministic Mersenne Twister pseudorandom number generator allows an attacker, with knowledge of the input seed, to replicate encryption keys. Consequently, this could enable unauthorized access to stored API keys and authentication tokens, posing a significant risk to data confidentiality and integration security.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kolega.dev (kolega-ai-dev) https://kolega.dev
.