PT-2026-50598 · Langflow · Langflow

·

CVE-2026-55450

·

Published

2026-06-17

·

Updated

2026-06-26

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.9.1
Description Unauthenticated users with network access can upload unlimited amounts of data to the server, which can lead to disk space exhaustion and a resulting denial-of-service. Additionally, the server response discloses the absolute path of the uploaded file, creating an information leak that could be used to facilitate further attacks. This issue occurs at the '/api/v1/upload/{flow id}' endpoint via the create upload file() function, where there is a lack of authentication and validation for the flow id variable. Over 38,300 potentially affected instances were identified via FOFA.
Recommendations Update to version 1.9.1. As a temporary workaround, restrict network access to the '/api/v1/upload/{flow id}' endpoint to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Information Disclosure

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55450
GHSA-X223-P2GF-V735
PYSEC-2026-224

Affected Products

Langflow