{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/langflow-oss-1.0.0-through-1.9.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-19297"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Langflow OSS (1.0.0 through 1.9.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Langflow OSS versions 1.0.0 through 1.9.6 contain a critical authentication vulnerability tracked as CVE-2026-19297. This flaw is classified under CWE-307: Improper Restriction of Excessive Authentication Attempts. The vulnerability permits a remote, unauthenticated attacker to execute high-frequency login requests against the application without encountering rate-limiting or account lockout mechanisms. This failure allows for effective brute-force or credential-stuffing attacks, potentially leading to unauthorized access to administrative or user accounts. Given the ease of exploitation (CVSS 3.1 base score of 9.1), defenders should prioritize identifying exposed instances and monitoring authentication endpoints for anomalous traffic patterns.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to user accounts. Depending on the privileges of the targeted account, an attacker could gain full control over the Langflow instance, access sensitive data, or modify workflows. This poses a significant risk to organizations using Langflow OSS for sensitive automation or data processing tasks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all internet-facing or internal instances of IBM Langflow OSS 1.0.0 through 1.9.6.\u003c/li\u003e\n\u003cli\u003eUpgrade affected Langflow OSS installations to the latest patched version provided by IBM.\u003c/li\u003e\n\u003cli\u003eImplement rate limiting or WAF-based blocking for login endpoints if patching cannot be performed immediately.\u003c/li\u003e\n\u003cli\u003eReview web server logs for high-frequency POST requests to authentication endpoints originating from single source IPs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T22:05:10Z","date_published":"2026-08-13T22:05:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-langflow-auth-bypass/","summary":"IBM Langflow OSS versions 1.0.0 through 1.9.6 are vulnerable to an authentication bypass flaw due to improper restriction of excessive authentication attempts, allowing remote attackers to potentially compromise user accounts.","title":"Authentication Bypass Vulnerability in IBM Langflow OSS","url":"https://feed.craftedsignal.io/briefs/2026-08-langflow-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Langflow OSS (1.0.0 Through 1.9.6)","version":"https://jsonfeed.org/version/1.1"}