CVE-2026-7754: Langflow

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

Affected products

  • Langflow Langflow: from 1.0.0, before 1.10.1 (fixed in 1.10.1)

Published 2026-07-17. Last modified 2026-07-21.