Vulnerability Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | < 1.0.19 |
Related Weaknesses (CWE)
References
- https://github.com/langflow-ai/langflow/pull/3923Issue TrackingPatch
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9ExploitPatchVendor Advisory
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9ExploitPatchVendor Advisory
FAQ
What is CVE-2026-55446?
CVE-2026-55446 is a vulnerability with a CVSS score of 7.5 (HIGH). Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse ...
How severe is CVE-2026-55446?
CVE-2026-55446 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55446?
Check the references section above for vendor advisories and patch information. Affected products include: Langflow Langflow.