IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
IBM recommends addressing the vulnerability now by upgrading to Langflow OSS 1.10.0 or newer https://pypi.org/project/langflow/