CVE-2026-7874: Weak Cryptographic Key Derivation Exposed All Stored Credentials
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7874?
The severity of CVE-2026-7874 is rated as critical with a score of 9.1.
How do I fix CVE-2026-7874?
To fix CVE-2026-7874, upgrade IBM Langflow OSS to version 1.10.1 or later which addresses the weak key derivation mechanism.
What does CVE-2026-7874 affect?
CVE-2026-7874 affects IBM Langflow OSS versions 1.0.0 through 1.10.0.
What vulnerabilities are associated with CVE-2026-7874?
CVE-2026-7874 is associated with the weak cryptographic key derivation and can lead to exposure of all stored credentials.
Who is affected by CVE-2026-7874?
Any organization using IBM Langflow OSS versions 1.0.0 to 1.10.0 is potentially affected by CVE-2026-7874.