Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-8470: IBM Langflow: Weak Encryption Keys Expose Stored API Keys

CVE-2026-8470 · published 1 month ago
Summary

IBM Langflow's encryption keys are generated using a weak method, allowing attackers to decrypt stored API keys and authentication tokens. This puts sensitive user information at risk. Update to the latest version of IBM Langflow to address this issue.

What to do
  • Update langflow langflow to version 1.11.0 or later.
Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.3
langflow langflow >= 1.0.0, < 1.11.0
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from u...
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
Severity
9.1 Critical
CVSS 3.1: 7.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-327Use of a Broken Cryptographic Algorithm
Timeline
Published5 Aug 2026
Updated25 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-8470 · NVD
CVE-2026-8470 · MITRE
Track software like this
Free during beta