CVE-2026-19305: Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
Other sources
Langflow OSS could allow a remote attacker to obtain sensitive information due to server-side request forgery.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it over the network. The vector indicates no privileges or user interaction are required.
What is the impact of successful exploitation?
Successful exploitation could allow an attacker to obtain sensitive information through server-side request forgery. The provided scoring indicates high confidentiality impact, with no stated integrity or availability impact.
Which releases are affected?
IBM Langflow OSS versions 1.0.0 through 1.11.2 are identified as affected.