
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19304 is a Server-Side Request Forgery (SSRF) vulnerability in IBM Langflow OSS that allows a remote authenticated attacker to obtain sensitive information from internal services by exploiting a URL parser discrepancy. It affects IBM Langflow OSS versions 1.0.0 through 1.11.2 (fixed in 1.11.3). The vulnerability was published on September 4, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (IBM Advisory).
The root cause is a URL parser discrepancy (CWE-918: Server-Side Request Forgery) within IBM Langflow OSS, where inconsistencies between how the application parses and validates URLs versus how the underlying HTTP client resolves them can be abused to bypass SSRF protections. An authenticated attacker with low privileges can craft a malicious URL that passes the application's validation logic but is ultimately resolved to an internal/private network address by the server, enabling access to internal services. This class of vulnerability — sometimes called "parser confusion" — exploits differences in URL parsing behavior between security filters and HTTP libraries (IBM Advisory, Dev.to Write-up).
Successful exploitation allows a remote authenticated attacker to make the Langflow server issue requests to internal services that would otherwise be inaccessible from the public network, resulting in high confidentiality impact with no integrity or availability impact. Sensitive information such as internal API responses, cloud metadata endpoints (e.g., AWS IMDSv1), internal configuration data, or credentials stored in internal services could be exposed. The changed scope in the CVSS vector indicates that the impact extends beyond the vulnerable component itself to other internal systems (IBM Advisory).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation for CVE-2026-19304. The EPSS score is approximately 0.307%, indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (IBM Advisory).
http://attacker.com@169.254.169.254/).http://169.254.169.254/latest/meta-data/.IBM has released IBM Langflow OSS version 1.11.3 to address this vulnerability; users should upgrade immediately (IBM Advisory). As interim mitigations, implement network segmentation to restrict the Langflow server's ability to reach internal services and cloud metadata endpoints. Apply strict authentication and authorization controls to limit which users can access Langflow functionality that processes external URLs. Consider deploying an egress firewall or proxy that blocks requests from the Langflow host to internal IP ranges.
A technical write-up on Dev.to titled "CVE-2026-19304: Bypassing SSRF Guards with Parser Confusion" discusses the URL parser discrepancy technique underlying this vulnerability (Dev.to Write-up). Additional Dev.to posts have explored related SSRF guard bypass themes in the context of AI agent frameworks, reflecting broader community interest in SSRF risks in LLM/AI pipeline tools (Dev.to Agent Post). Coverage has also appeared on threat intelligence aggregators such as VulDB and radar.offseq.com.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."