CVE-2026-12767: Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches
IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Other sources
Langflow is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Frequently Asked Questions
Does an attacker need to authenticate to exploit this issue?
No. The vulnerability is described as exploitable by an unauthenticated attacker.
What deployment scope is identified?
The provided information identifies IBM Langflow OSS. It does not specify affected versions, configuration prerequisites, or whether default deployments are affected.