Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption. | |
| Title | Flowise before 3.1.4 Denial of Service via text-to-speech/abort | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T12:08:44.062Z
Reserved: 2026-09-12T11:12:50.791Z
Link: CVE-2026-90535
No data.
Status : Received
Published: 2026-09-12T13:16:51.380
Modified: 2026-09-12T13:16:51.380
Link: CVE-2026-90535
No data.
OpenCVE Enrichment
Updated: 2026-09-12T16:45:07Z
Weaknesses