Description
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.0 https://pypi.org/project/langflow/
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7277996 |
|
History
Tue, 30 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service. | |
| Title | Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS | |
| First Time appeared |
Ibm
Ibm langflow Oss |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_oss:1.9.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Oss |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-06-30T19:53:20.632Z
Reserved: 2026-06-01T15:10:29.825Z
Link: CVE-2026-10560
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T21:30:17Z
Weaknesses