Skip to content
IBMCVE-2026-18545

IBM Langflow OSS: server-side request forgery

Medium4.3CVE-2026-18545 · Published Aug 28, 2026 · updated Aug 31, 2026

IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

IBM advisory

Affected versions

PackageAffectedFixed in
Langflow OSS
Product
>= 1.0.0, <= 1.11.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More IBM advisories

All IBM
Advisory
IBM Concert: SQL injection
Critical9.1Aug 28
IBM Cloud Pak for Data System: denial of service
Medium6.2Aug 28
IBM Langflow OSS: path traversal
High7.5Aug 28
IBM Langflow OSS: information disclosure
High8.2Aug 28
IBM Langflow OSS: remote code execution
Critical9.8Aug 28
IBM Langflow OSS: improper authorization
Medium6.4Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.