Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6128 articles · 219977 vulns · 37/41 feeds (7d)
← Back to list
7.4
CVE-2026-8470PATCHED
langflow · langflow

Langflow is affected by weaknesses in secret handling and sensitive configuration access

Description

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.

Affected Products

VendorProductVersions
langflowlangflow1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmlangflowcert_advisory90%

References

  • https://www.ibm.com/support/pages/node/7282648(vendor-advisory, patch)

Related News (2 articles)

Tier B
BSI Advisories46d ago
[NEU] [hoch] IBM Langflow Desktop: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB46d ago
CVE-2026-8470 | IBM Langflow OSS up to 1.10.3 entropy
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.4 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ibm.com/support/pages/node/7282648
CWECWE-327
PublishedAug 5, 2026
Trending Score0
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-9198EXPKEV
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
Trending: 10
HIGHCVE-2026-9196
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-8478
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-17632
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-9081
Langflow OSS is affected by server-side request forgery in provider validation and API request functionality

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026
Patch Available
Aug 5, 2026