PT-2026-51101 · Langflow · Langflow

·

CVE-2026-55446

·

Published

2026-06-19

·

Updated

2026-06-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.0.19
Description An unauthenticated attacker can cause a denial of service by sending a request to the '/api/v1/files/upload/' endpoint without authentication tokens or cookies. By abusing a very long multipart form boundary, such as including an extremely large amount of hyphens, the application attempts to process the malformed data before performing authentication or flow-ownership checks. This process can make the application unusable for all users for an indefinite period. The attack does not require a valid flow UUID, as the server attempts to process the boundary regardless of the value provided.
Recommendations Update to version 1.0.19.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55446
GHSA-QWQC-P3Q8-WCG9
PYSEC-2026-223

Affected Products

Langflow