CVE-2026-55450
CRITICAL NUCLEILangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Title source: cnaExploitation Summary
CVE-2026-55450 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.
Nuclei Templates (1)
Langflow < 1.9.1 - Unauthenticated File Upload
CRITICALVERIFIEDby xtr0nix
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/langflow-ai/langflow/security/advisories/GHSA-x223-p2gf-v735
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/12831
Scores
CVSS v3
9.3
EPSS
0.0640
EPSS Percentile
93.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
CWE-306
CWE-400
Status
published
Products (2)
langflow/langflow
< 1.9.1
langflow-ai/langflow
< 1.9.1
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026