[UPDATE] [hoch] Langflow OSS: Mehrere Schwachstellen
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Langflow OSS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, sensible Daten offenzulegen oder zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuführen.
CSIRTS triage
- What
- Multiple critical vulnerabilities including arbitrary code execution, SSRF, privilege bypass, and cross-site scripting in Langflow OSS.
- Who is affected
- Authenticated users and potentially anonymous attackers on exposed Langflow OSS instances.
- Urgency
- High; remote code execution vulnerability with multiple attack vectors makes this urgent for internet-facing deployments.
- Action
- Immediately apply available patches or upgrade to latest Langflow OSS version; restrict network access until patched.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Langflow OSS
Get an email when a new Langflow OSS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3096
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12763 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12765 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12766 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17631 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19298 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19299 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19300 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19301 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19303 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19305 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19306 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8447 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9138 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9186 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-17631: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain se…nvd
- highCVE-2026-19306: IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files…nvd
- highCVE-2026-19305: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive inform…nvd
- highCVE-2026-19304: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain se…nvd
- highCVE-2026-19303: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete ar…nvd
- mediumCVE-2026-19302: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain se…nvd
- mediumCVE-2026-19301: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain se…nvd
- highCVE-2026-19300: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive inform…nvd
- mediumCVE-2026-19299: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain se…nvd
- highCVE-2026-19298: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute a…nvd
- mediumCVE-2026-9186: IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost…nvd
- mediumCVE-2026-9138: IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write a…nvd
Recent advisories for Langflow OSS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-17631: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain se…nvd · 2026-09-04
- mediumCVE-2026-17627: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain se…nvd · 2026-09-04
- mediumCVE-2026-17622: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain se…nvd · 2026-09-04
- mediumCVE-2026-17621: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on…nvd · 2026-09-04
- mediumCVE-2026-14470: IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse direct…nvd · 2026-09-04
- highCVE-2026-19306: IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files…nvd · 2026-09-04
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen2026-09-07
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen2026-09-07
- high[UPDATE] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-07
- high[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen2026-09-07