CVE-2026-10560: Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/buildpublictmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
Other sources
Langflow OSS contains a missing authentication vulnerability in /api/v1/buildpublictmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10560?
CVE-2026-10560 has a severity rating of 9.1, classified as critical.
What is the risk associated with CVE-2026-10560?
CVE-2026-10560 presents a risk score of 66, indicating significant potential impact.
How do I fix CVE-2026-10560?
To fix CVE-2026-10560, users should upgrade to a patched version of IBM Langflow OSS that mitigates this vulnerability.
What types of information can be accessed due to CVE-2026-10560?
CVE-2026-10560 allows unauthenticated attackers to access sensitive build event data.
What are the potential consequences of CVE-2026-10560?
The potential consequences of CVE-2026-10560 include unauthorized information disclosure and denial of service.