CVE-2026-10546: DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component
IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/datasource/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding.
Other sources
Langflow OSS contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component (
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10546?
The severity of CVE-2026-10546 is high, with a score of 7.1.
How do I fix CVE-2026-10546?
To mitigate CVE-2026-10546, upgrade IBM Langflow OSS to version 1.9.4 or later.
What types of vulnerabilities are associated with CVE-2026-10546?
CVE-2026-10546 is associated with Server-Side Request Forgery (SSRF) and race condition vulnerabilities.
What can be exploited in CVE-2026-10546?
CVE-2026-10546 can be exploited via DNS rebinding to bypass SSRF protection.
Which versions of Langflow OSS are affected by CVE-2026-10546?
IBM Langflow OSS versions 1.0.0 through 1.9.3 are affected by CVE-2026-10546.