Server-Side Request Forgery in IBM Langflow OSS Affects Key Functionality
CVE-2026-9081

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-9081?

A Server-Side Request Forgery (SSRF) vulnerability exists in IBM Langflow OSS versions 1.0.0 to 1.10.3, specifically within the validate_model_provider_key() function associated with the Ollama provider. This vulnerability arises from the function's lack of validation, scheme and host allowlisting, and insufficient filtering of private IP ranges, such as loopback and RFC1918 addresses. As a result, an attacker could exploit this flaw to send unauthorized requests, potentially leading to exposure of sensitive information and increased risk within the affected environment.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.