CVE-2026-19297: Insufficient Authentication Brute Force Protection on Login Endpoint
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
Other sources
Langflow OSS could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0