nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8470 CVE-2026-8470
HIGH
Langflow is affected by weaknesses in secret handling and sensitive configuration access
Record summary
CVE-2026-8470 has a selected CVSS score of 7.4 (high).
Description
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Langflow OSSBrowse IBM / Langflow OSS | CVE List | 1.0.0 to ≤ 1.10.3 | affected |
References
2ibm.comVendor advisorypatch
https://www.ibm.com/support/pages/node/7282648