CVE-2026-19297: Insufficient Authentication Brute Force Protection on Login Endpoint
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
Other sources
Langflow OSS could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19297?
CVE-2026-19297 has a critical severity rating of 9.1.
How do I fix CVE-2026-19297?
To mitigate CVE-2026-19297, update IBM Langflow OSS to a patched version released after 1.9.6.
What types of attacks are possible with CVE-2026-19297?
CVE-2026-19297 allows attackers to perform brute force attacks on the login endpoint, leading to unauthorized access.
Which versions of IBM Langflow OSS are affected by CVE-2026-19297?
CVE-2026-19297 affects IBM Langflow OSS versions 1.0.0 through 1.9.6.
Is there a workaround for CVE-2026-19297 before updating?
Implement rate limiting on the login endpoint to help mitigate the risks associated with CVE-2026-19297 until a full update can be applied.