SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-7754

HIGH · CVSS 7.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.0, including 1.9.0, are vulnerable to server-side request forgery (SSRF) due to insecure default configurations and inadequate enforcement of SSRF protections. This vulnerability could allow attackers to manipulate server requests, potentially leading to unauthorized access to internal resources. Organizations using affected versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-7754
Severity
HIGH
CVSS
7.7
EPSS
0.20%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

Related CVEs

Other vulnerabilities affecting the same vendor(s)