Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-19297: IBM Langflow OSS: Unauthorized Login Attempts
CVE-2026-19297 · published 1 month ago
Summary
IBM Langflow OSS has a security issue that allows attackers to try many login combinations without being blocked. This could let an attacker guess a user's password and gain access to their account. To stay safe, update IBM Langflow OSS to the latest version.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.9.6 |
Original advisory text
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
References
- https://www.ibm.com/support/pages/node/7283558 vendor-advisory patch
Severity
9.1
Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-307Improper Restriction of Excessive Authentication Attempts
Timeline
Published13 Aug 2026
Updated25 Sep 2026
First seen13 Aug 2026
Track software like this
Free during beta