CVE-2024-9277: Langflow HTTP POST Request utils.py redos
A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipulation of the argument remainingtext leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9277?
CVE-2024-9277 is classified as problematic which indicates a moderate risk to affected systems.
How do I fix CVE-2024-9277?
To fix CVE-2024-9277, it is recommended to update Langflow to version 1.0.19 or later.
What component is affected by CVE-2024-9277?
CVE-2024-9277 affects the HTTP POST Request Handler functionality in Langflow's utils.py file.
Which versions of Langflow are impacted by CVE-2024-9277?
CVE-2024-9277 impacts Langflow versions up to and including 1.0.18.
What type of vulnerability is CVE-2024-9277?
CVE-2024-9277 is categorized as a vulnerability that may lead to remote denial of service (DoS) attacks.