IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
Advisories
No advisories yet.
Fixes
Solution
IBM recommends addressing the vulnerability now by upgrading to Langflow OSS 1.10.0 or newer https://pypi.org/project/langflow/
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283558 |
|
History
Thu, 13 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | |
| Title | Insufficient Authentication Brute Force Protection on Login Endpoint | |
| First Time appeared |
Ibm
Ibm langflow Oss |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_oss:1.9.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Oss |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-13T20:46:44.813Z
Reserved: 2026-08-07T17:10:50.493Z
Link: CVE-2026-19297
No data.
Status : Received
Published: 2026-08-13T21:17:45.870
Modified: 2026-08-13T21:17:45.870
Link: CVE-2026-19297
No data.
OpenCVE Enrichment
Updated: 2026-08-14T00:00:03Z
Weaknesses