CVE-2026-7528: Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS
Published May 19, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
Other sources
Langflow OSS could allow a denial of service due to uncontrolled resource consumption.
— IBM
Affected Software
2 affected components
IBM Langflow OSS<=1.0.0-1.9.0
Langflow Langflow>=1.0.0<=1.9.0
Remediation
Information
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.9.2.
Event History
May 19, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
May 27, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7528?
The severity of CVE-2026-7528 is rated as high with a score of 7.5.
2
What are the impacts of CVE-2026-7528?
CVE-2026-7528 can lead to denial of service due to uncontrolled resource consumption, along with potential path disclosure.
3
How do I fix CVE-2026-7528?
To fix CVE-2026-7528, upgrade IBM Langflow OSS to version 1.9.2 or later.
4
Which versions of IBM Langflow OSS are affected by CVE-2026-7528?
IBM Langflow OSS versions 1.0.0 through 1.9.0 are affected by CVE-2026-7528.
5
What can be done to mitigate risks associated with CVE-2026-7528 until a fix is applied?
To mitigate risks from CVE-2026-7528, implement strict access controls and monitor resource usage until a proper upgrade can be performed.