CVE-2026-10129
IBM Langflow OSS, langflow
IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects parameter and supplying a public URL that redirects to internal/localhost addresses. The vulnerability exists because the application validates only the initial URL but does not re-validate redirect destinations. This allows attackers to access internal HTTP services, localhost endpoints, cloud metadata services, and p...
- CVSS
- 8.5
- EPSS
- 0.18% 8.37% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01