LangflowGHSA-355v-2rjx-fpx7
Inefficient Regular Expression Complexity in langflow
Medium3.5CVE-2024-9277 · Published Sep 27, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | <= 1.0.18 | No fix yet |
Details and references
A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipulation of the argument remaining_text leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1333
- Also known as
- CVE-2024-9277, PYSEC-2026-1521
- nvd.nist.gov/vuln/detail/CVE-2024-9277
- github.com/langflow-ai/langflow
- github.com/langflow-ai/langflow/blob/main/src/backend/base/langflow/interface/utils.py#L65
- rumbling-slice-eb0.notion.site/Remote-Redos-in-https-github-com-langflow-ai-langflow-067159ced0d5494e91b06071384969c4?pvs=4
- vuldb.com/?ctiid.278659
- vuldb.com/?id.278659
- vuldb.com/?submit.410043
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | langflow has vulnerability in PythonCodeTool component CVE-2024-42835High9.8no fix yet | High9.8 | No fix yet |
| Nov 52024 | Langflow vulnerable to remote code execution CVE-2024-48061Medium9.8no fix yet | Medium9.8 | No fix yet |
| Jun 102024 | Langflow remote code execution vulnerability CVE-2024-37014High8.8fixed in 1.0.15 | High8.8 | 1.0.15 |
| Jun 172025 | Langflow Unauth RCE CVE-2025-3248Criticalfixed in 1.3.0 | Critical | 1.3.0 |
| Aug 252025 | Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE) CVE-2025-57760High8.8fixed in 1.5.1 | High8.8 | 1.5.1 |
| Dec 62025 | Langflow CORS misconfiguration enables Account Takeover and RCE CVE-2025-34291Critical8.8fixed in 1.7.0 | Critical8.8 | 1.7.0 |