Server-Side Request Forgery in IBM Langflow OSS Affects Key Functionality
CVE-2026-9081
7.1HIGH
What is CVE-2026-9081?
A Server-Side Request Forgery (SSRF) vulnerability exists in IBM Langflow OSS versions 1.0.0 to 1.10.3, specifically within the validate_model_provider_key() function associated with the Ollama provider. This vulnerability arises from the function's lack of validation, scheme and host allowlisting, and insufficient filtering of private IP ranges, such as loopback and RFC1918 addresses. As a result, an attacker could exploit this flaw to send unauthorized requests, potentially leading to exposure of sensitive information and increased risk within the affected environment.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3