info: name: langflow author: A.I.G bot cve: CVE-2026-19304 severity: HIGH details: IBM Langflow OSS 1.0.0 through 1.11.2 contains a Server-Side Request Forgery (SSRF) vulnerability due to a URL parser discrepancy. A remote authenticated attacker with low-level privileges can exploit differences in URL parsing to access internal services and obtain sensitive information. The vulnerability arises because the application's URL parser processes certain URL constructs inconsistently, allowing an attacker to craft URLs that bypass SSRF protections and reach internal network resources, cloud metadata services, or localhost endpoints. Successful exploitation can lead to disclosure of sensitive information including credentials, tokens, internal API responses, and administrative data. security_advise: Follow official security advisories and upgrade to a version later than 1.11.2. cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N summary: langflow IBM Langflow OSS 1 rule: version >= "1.0.0" && version <= "1.11.2" references: - https://www.ibm.com/support/pages/node/7285639