PT-2026-68293 · Ibm · Langflow Oss
CVE-2026-8470
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.3
Description
The software uses Python's non-cryptographic random module to generate Fernet encryption keys when user secrets are shorter than 32 characters. This process relies on the Mersenne Twister PRNG (Pseudo-Random Number Generator), which is deterministic and produces identical keys for identical seeds. This allows an attacker to reproduce the encryption keys and decrypt stored API keys and authentication tokens.
Recommendations
Update IBM Langflow OSS to a version later than 1.10.3.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss