PT-2026-51101 · Langflow · Langflow
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Langflow versions prior to 1.0.19
Description
An unauthenticated attacker can cause a denial of service by sending a request to the '/api/v1/files/upload/' endpoint without authentication tokens or cookies. By abusing a very long multipart form boundary, such as including an extremely large amount of hyphens, the application attempts to process the malformed data before performing authentication or flow-ownership checks. This process can make the application unusable for all users for an indefinite period. The attack does not require a valid flow UUID, as the server attempts to process the boundary regardless of the value provided.
Recommendations
Update to version 1.0.19.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow