CVE-2026-3341: IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services
IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow Desktopto a version that resolves this vulnerability.Fixed in 1.9.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3341?
The severity of CVE-2026-3341 is medium with a score of 5.4.
How do I fix CVE-2026-3341?
To fix CVE-2026-3341, update IBM Langflow Desktop to a version beyond 1.9.2.
What vulnerabilities are associated with CVE-2026-3341?
CVE-2026-3341 is associated with server-side request forgery (SSRF) vulnerabilities.
Who is affected by CVE-2026-3341?
All users of IBM Langflow Desktop versions 1.0.0 through 1.9.2 are affected by CVE-2026-3341.
What attack methods are enabled by CVE-2026-3341?
CVE-2026-3341 may enable attackers to send unauthorized requests, potentially allowing network enumeration or other types of attacks.