mediumCVSS 7.3Vulnerability

CVE-2026-6596

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
epss_score
0.00284
cvss_score
7.3
ghsa_published
2026-04-20T03:34:42Z
source_url
https://github.com/advisories/GHSA-vvfc-fp59-m92g
ghsa_updated
2026-04-24T20:13:27Z
ghsa_id
GHSA-vvfc-fp59-m92g
cve_id
CVE-2026-6596
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.20614

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/langflow-base

AFFECTS (1)

[Software]pip/langflow-base

Explore deeper with Ninja Signal's threat intelligence graph