nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-7657 CVE-2026-7657
MEDIUM
Langflow OSS is affected by server-side request forgery in provider validation and API request functionality
Record summary
CVE-2026-7657 has a selected CVSS score of 6.5 (medium).
Description
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Langflow OSSBrowse IBM / Langflow OSS | CVE List | 1.0.0 to ≤ 1.10.3 | affected |
References
2ibm.comVendor advisorypatch
https://www.ibm.com/support/pages/node/7282650