Weak Cryptographic Key Derivation in IBM Langflow OSS Software
CVE-2026-9205

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-9205?

IBM Langflow OSS is affected by a vulnerability in its ensure_fernet_key() function, which utilizes a weak cryptographic key derivation technique. This flaw may allow attackers to exploit weak keys, undermining the security of cryptographic practices within the software. Organizations using this affected version should adopt recommended security practices and install any available patches to mitigate exposure.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kolega.dev (kolega-ai-dev) https://kolega.dev
.