Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-8470: IBM Langflow: Weak Encryption Keys Expose Stored API Keys

CVE-2026-8470 CVE-2026-8470
Summary

IBM Langflow's encryption keys are generated using a weak method, allowing attackers to decrypt stored API keys and authentication tokens. This puts sensitive user information at risk. Update to the latest version of IBM Langflow to address this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.3
langflow langflow >= 1.0.0, < 1.11.0
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original title
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from u...
Original description
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
nvd CVSS3.1 7.4
Vulnerability type
CWE-327 Use of a Broken Cryptographic Algorithm
Published: 5 Aug 2026 · Updated: 7 Aug 2026 · First seen: 5 Aug 2026