Weak Cryptographic Key Derivation in IBM Langflow OSS Software
CVE-2026-9205
7.4HIGH
What is CVE-2026-9205?
IBM Langflow OSS is affected by a vulnerability in its ensure_fernet_key() function, which utilizes a weak cryptographic key derivation technique. This flaw may allow attackers to exploit weak keys, undermining the security of cryptographic practices within the software. Organizations using this affected version should adopt recommended security practices and install any available patches to mitigate exposure.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3