CVE-2026-12767: SSRF
Published Sep 8, 2026
·Updated
Langflow is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.5
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Does an attacker need to authenticate to exploit this issue?
No. The vulnerability is described as exploitable by an unauthenticated attacker.
2
What deployment scope is identified?
The provided information identifies IBM Langflow OSS. It does not specify affected versions, configuration prerequisites, or whether default deployments are affected.