CVE-2026-7754: SSRF Protection Configuration Vulnerability
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7754?
The severity of CVE-2026-7754 is assessed as high, with a CVSS score of 7.7.
How do I fix CVE-2026-7754?
To fix CVE-2026-7754, review and update the SSRF protection configuration in IBM Langflow to ensure it enforces secure settings.
What type of vulnerability is CVE-2026-7754?
CVE-2026-7754 is identified as a server-side request forgery (SSRF) protection configuration vulnerability.
Which versions of IBM Langflow are affected by CVE-2026-7754?
CVE-2026-7754 affects IBM Langflow OSS versions 1.0.0 through 1.10.0 and Langflow version 1.9.0.
What security risks does CVE-2026-7754 pose?
CVE-2026-7754 poses the risk of allowing unauthorized SSRF attacks due to insecure default configurations.