Unauthenticated Denial of Service in Flowise by FlowiseAI
CVE-2026-90535

6.3MEDIUM

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90535?

Flowise versions prior to 3.1.4 are susceptible to an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint. This vulnerability allows attackers to disrupt service by sending requests with specific chatflowId and chatId without verifying ownership, enabling them to terminate active chat flow predictions for any user. Consequently, this can lead to significant disruptions in service, impacting user experience and application reliability.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.