CVE-2026-93679: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.
Other sources
Langflow OSS could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected. Exploitation requires an authenticated remote attacker with low-level privileges.
What is the impact of successful exploitation?
An attacker can trigger uncontrolled resource consumption during ZIP file extraction, causing a denial of service. The provided severity vector indicates no stated confidentiality or integrity impact.