Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-8470: IBM Langflow: Weak Encryption Keys Expose Stored API Keys
CVE-2026-8470 · published 1 month ago
Summary
IBM Langflow's encryption keys are generated using a weak method, allowing attackers to decrypt stored API keys and authentication tokens. This puts sensitive user information at risk. Update to the latest version of IBM Langflow to address this issue.
What to do
- Update langflow langflow to version 1.11.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.3 |
| langflow | langflow |
>= 1.0.0, < 1.11.0 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from u...
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
Severity
9.1
Critical
CVSS 3.1: 7.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-327Use of a Broken Cryptographic Algorithm
Timeline
Published5 Aug 2026
Updated25 Sep 2026
First seen5 Aug 2026
Track software like this
Free during beta