CVE-2026-19305
8.6IBM · Langflow OSS
A server-side request forgery vulnerability in IBM Langflow OSS allows unauthenticated remote attackers to access sensitive information.
Executive summary
A critical server-side request forgery vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.2 allows remote, unauthenticated attackers to exfiltrate sensitive data.
Vulnerability
The application is susceptible to Server-Side Request Forgery (CWE-918), which allows an unauthenticated remote attacker to perform unauthorized requests from the server to internal resources.
Business impact
Successful exploitation of this flaw allows attackers to bypass network perimeters and access internal services or sensitive configuration data, potentially leading to a full compromise of internal application state or data exfiltration. With a CVSS score of 8.6, this vulnerability represents a high risk to organizational security, particularly if the affected instance resides within a trusted internal network segment.
Remediation
Immediate Action: Upgrade IBM Langflow OSS to version 1.11.3 or later as specified in the vendor security advisory.
Proactive Monitoring: Review web server and application access logs for unusual outbound requests or suspicious URI patterns directed toward internal infrastructure.
Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect and block outbound requests that attempt to access internal IP addresses or sensitive local endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity and the potential for unauthorized access to sensitive internal resources, organizations should prioritize patching this vulnerability immediately. Upgrading to version 1.11.3 is the only reliable method to mitigate the risk of server-side request forgery in this environment.