CVE-2026-9205
### Summary Langflow uses Python's `random` module (Mersenne Twister, a non-cryptographic PRNG) seeded with the `SECRET_KEY` to derive the Fernet encryption key for all stored user credentials (API keys, LLM provider secrets, database passwords). When the `SECRET_KEY` is shorter than 32 characters — a common scenario for self-hosted deployments using simple/memorable secrets — the derived encryption key is fully deterministic and reproducible by anyone who knows the seed value. An attacker who obtains the `SECRET_KEY` (e.g., via the MCP path traversal in this repo) can reconstruct the exact Fernet key offline and decrypt every credential stored in the database with no brute force required. Even when `SECRET_KEY` is 32+ characters (the "safe" branch), the raw key material is used directly as the Fernet key — meaning exfiltrating the `secret_key` file is sufficient to decrypt all credentials without any additional computation. **Severity:** Critical — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1) **CWE-338:** Weak PRNG | **CWE-321:** Hard-coded Cryptographic Key | **CWE-311:** Missing Encryption of Sensitive Data ### Details **Root cause: `src/backend/base/langflow/services/auth/service.py`, lines 651–663** ```python MINIMUM_KEY_LENGTH = 32 def _ensure_valid_key(self, raw_key: str) -> bytes: if len(raw_key) < MINIMUM_KEY_LENGTH: random.seed(raw_key) # Non-cryptographic PRNG seeded with the secret key = bytes(random.getrandbits(8) for _ in range(32)) # Fully deterministic output key = base64.urlsafe_b64encode(key) else: key = self._add_padding(raw_key).encode() # Raw secret IS the Fernet key return key def _get_fernet(self) -> Fernet: secret_key = self.settings.auth_settings.SECRET_KEY.get_secret_value() valid_key = self._ensure_valid_key(secret_key) return Fernet(valid_key) ``` The identical logic is duplicated in `src/backend/base/langflow/services/aut
Properties
- severity
- critical
- summary
- Langflow: Weak Fernet Key via random.seed()
- epss_score
- 0.00417
- cvss_score
- 9.1
- retrieved_at
- 2026-10-05T22:59:58+00:00
- ghsa_published
- 2026-10-05T22:31:35Z
- source_url
- https://github.com/advisories/GHSA-jxw3-mjmx-3pqm
- ghsa_updated
- 2026-10-05T22:31:37Z
- ghsa_id
- GHSA-jxw3-mjmx-3pqm
- last_source
- FIRST EPSS
- cve_id
- CVE-2026-9205
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- signal_observed_at
- 2026-10-05T22:52:21+00:00
- is_ghsa_only
- false
- epss_percentile
- 0.33756
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph