CVE-2026-7657: Langflow OSS is affected by server-side request forgery in provider validation and API request functionality
Published Aug 5, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
Affected Software
2 affected components
IBM Langflow OSS>=1.0.0<=1.10.3
IBM Langflow OSS<=1.0.0-1.10.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Aug 5, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
RemedyDescriptionSeverityWeakness