CVE-2026-41272: Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via DNS Rebinding (Time-of-Check Time-of-Use) or by exploiting the default configuration which fails to enforce any deny list. This vulnerability is fixed in 3.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41272?
CVE-2026-41272 is classified as a high severity vulnerability due to its potential for Server-Side Request Forgery (SSRF) exploitation.
How do I fix CVE-2026-41272?
To fix CVE-2026-41272, upgrade to Flowise version 3.1.0 or later, which includes the necessary security improvements.
Which versions of Flowise are affected by CVE-2026-41272?
Flowise versions prior to 3.1.0 are affected by CVE-2026-41272.
What type of vulnerability is CVE-2026-41272?
CVE-2026-41272 is a Server-Side Request Forgery (SSRF) vulnerability that may compromise application security.
What are the implications of CVE-2026-41272?
The implications of CVE-2026-41272 include the potential for an attacker to exploit the vulnerability and make unauthorized requests to internal systems.