CVE-2026-81265: CWE-918 Server-Side Request Forgery (SSRF) in IBM Langflow OSS
Severity: highType: VulnerabilityCVE-2026-81265
IBM Langflow OSS 1.0.0 through 1.11.5.
CVE-2026-81265: CWE-918 Server-Side Request Forgery (SSRF) in IBM Langflow OSS
0
HighPublished: 09/10/2026 (09/10/2026, 21:31:41 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Langflow OSS
Description
IBM Langflow OSS 1.0.0 through 1.11.5.
CVSS v3.1
Score 7.5high
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected software
IBM
Langflow OSS
Affected versions
>=1.0.0 <=1.11.5
CPE configurations (2)
cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*Weaknesses
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ibm
- Date Reserved
- 2026-08-26T17:07:46.074Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa3258a91cc7f3848ca5c58
Added to database: 09/10/2026, 21:47:54 UTC
Last updated: 09/10/2026, 21:47:54 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Sort by
Loading community insights…
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Please log in to the Console to use AI analysis features.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Breach by OffSeqOFFSEQFRIENDS — 25% OFF
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
OffSeq TrainingCredly Certified
Lead Pen Test Professional
Technical5-day eLearningPECB Accredited