Vulnerability Description
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.0.0, < 1.11.0 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7282648Vendor Advisory
FAQ
What is CVE-2026-8470?
CVE-2026-8470 is a vulnerability with a CVSS score of 7.4 (HIGH). IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user...
How severe is CVE-2026-8470?
CVE-2026-8470 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8470?
Check the references section above for vendor advisories and patch information. Affected products include: Langflow Langflow.