Skip to content
LangflowGHSA-355v-2rjx-fpx7

Inefficient Regular Expression Complexity in langflow

Medium3.5CVE-2024-9277 · Published Sep 27, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
<= 1.0.18No fix yet
Details and references

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipulation of the argument remaining_text leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1333
Also known as
CVE-2024-9277, PYSEC-2026-1521

More Langflow advisories

All Langflow
DateAdvisory
Oct 312024langflow has vulnerability in PythonCodeTool component
CVE-2024-42835High9.8no fix yet
Nov 52024Langflow vulnerable to remote code execution
CVE-2024-48061Medium9.8no fix yet
Jun 102024Langflow remote code execution vulnerability
CVE-2024-37014High8.8fixed in 1.0.15
Jun 172025Langflow Unauth RCE
CVE-2025-3248Criticalfixed in 1.3.0
Aug 252025Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-57760High8.8fixed in 1.5.1
Dec 62025Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2025-34291Critical8.8fixed in 1.7.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.