
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17631 is a Server-Side Request Forgery (SSRF) vulnerability in IBM Langflow OSS that allows remote authenticated attackers to obtain sensitive information by making the server perform unauthorized HTTP requests. It affects IBM Langflow OSS versions 1.0.0 through 1.10.2 (fixed in 1.10.3). The vulnerability was published on September 4, 2026, with a patch referenced in the GitHub Advisory Database. It carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, and 5.0 (Moderate) per the GitHub Advisory (GitHub Advisory, IBM Support).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the web server retrieves the contents of a URL or request without sufficiently validating that the request targets an expected destination. An authenticated attacker with low-level privileges can craft malicious requests that cause the Langflow OSS server to issue HTTP requests to internal or external resources on the attacker's behalf. No user interaction is required, and the attack is conducted entirely over the network with low complexity. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, IBM Support).
Successful exploitation allows an authenticated attacker to access sensitive information not normally accessible to them, including data from internal network resources reachable by the Langflow OSS server. The impact is limited to confidentiality — there is no integrity or availability impact. In environments where the server has access to internal APIs, metadata services (e.g., cloud instance metadata endpoints), or other sensitive internal resources, the exposure risk can be significant (GitHub Advisory, IBM Support).
There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-17631. The NVD SSVC assessment confirms exploitation status as "none" and the technical impact as "partial," with automation assessed as "no." The EPSS score is approximately 0.197%, indicating a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory).
IBM has released a patch addressing this vulnerability; users should upgrade IBM Langflow OSS to version 1.10.3 or later. As a network-level workaround, administrators should implement network segmentation to restrict the Langflow server's ability to reach sensitive internal resources, such as cloud metadata endpoints (e.g., 169.254.169.254) and internal APIs. Applying allowlist-based egress filtering on outbound HTTP requests from the server is also recommended (GitHub Advisory, IBM Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."