CVE-2026-19297 PUBLISHED

Insufficient Authentication Brute Force Protection on Login Endpoint

Assigner: ibm
Reserved: 07.08.2026 Published: 13.08.2026 Updated: 13.08.2026

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor IBM
Product Langflow OSS
Versions
  • affected from 1.0.0 to 1.9.6 (incl.)

Solutions

IBM recommends addressing the vulnerability now by upgrading to Langflow OSS 1.10.0 or newer https://pypi.org/project/langflow/

References

Problem Types

  • CWE-307 Improper Restriction of Excessive Authentication Attempts CWE