CVE-2026-7657: Langflow OSS is affected by server-side request forgery in provider validation and API request functionality
Published Aug 5, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
Affected Software
3 affected components
IBM Langflow OSS>=1.0.0<=1.10.3
IBM Langflow OSS<=1.0.0-1.10.3
Langflow Langflow>=1.0.0<1.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Aug 5, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7657?
CVE-2026-7657 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-7657?
To fix CVE-2026-7657, upgrade to a patched version of IBM Langflow OSS beyond 1.10.3.
3
What functionality is affected by CVE-2026-7657?
CVE-2026-7657 affects the provider validation and API request functionality within IBM Langflow OSS.
4
What type of vulnerability is CVE-2026-7657?
CVE-2026-7657 is categorized as a server-side request forgery (SSRF) vulnerability.
5
What versions of IBM Langflow OSS are impacted by CVE-2026-7657?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are impacted by CVE-2026-7657.