CVE-2026-10140: Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
Other sources
Langflow OSS voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10140?
CVE-2026-10140 has a critical severity rating of 9.6.
How do I fix CVE-2026-10140?
To fix CVE-2026-10140, update IBM Langflow OSS to a version beyond 1.10.0.
What type of vulnerability is CVE-2026-10140?
CVE-2026-10140 is a cross-tenant API key reuse vulnerability.
Who is affected by CVE-2026-10140?
Users of IBM Langflow OSS versions 1.0.0 to 1.10.0 are affected by CVE-2026-10140.
What can attackers do with CVE-2026-10140?
Attackers can exploit CVE-2026-10140 to manipulate cache state, leading to unauthorized access to API credentials.