CVE-2026-7871: Insecure Deserialization in Redis Cache Backend
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
Other sources
Langflow OSS allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7871?
The severity of CVE-2026-7871 is critical with a score of 9.8.
How do I fix CVE-2026-7871?
To fix CVE-2026-7871, upgrade to a patched version of IBM Langflow OSS beyond 1.10.0.
What systems are affected by CVE-2026-7871?
CVE-2026-7871 affects IBM Langflow OSS versions 1.0.0 through 1.10.0.
What type of vulnerability is CVE-2026-7871?
CVE-2026-7871 is an insecure deserialization vulnerability.
What impact can CVE-2026-7871 have?
CVE-2026-7871 can allow attackers with Redis access to execute arbitrary code, compromising application privileges and data security.