CVE-2026-17631: Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3 - Compensating control
Mitigate SSRF risk by ensuring missing URL validation in flow components is addressed (implement/enable URL validation for any server-side requests made from flow components), since the issue is described as missing URL validation in flow components.
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Langflow OSS versions 1.0.0 through 1.10.2 are affected.
What access does an attacker need to exploit this issue?
An attacker must be remotely authenticated to exploit the vulnerability. No user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation could allow the authenticated attacker to obtain sensitive information through server-side request forgery.