IBM Langflow OSS Uncontrolled Resource Consumption Leading to Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in IBM Langflow OSS versions 1.0.0 through 1.9.0. This issue arises from uncontrolled resource consumption, allowing unauthenticated users to upload an unlimited number of files via the deprecated /api/v1/upload/{flow_id} endpoint. The lack of authentication and validation enables potential disk space exhaustion and information disclosure through absolute file path leakage in API responses.

Impact

Exploitation of this vulnerability can lead to disk space exhaustion, causing a denial-of-service condition on the affected server.

Remediation

Users are advised to upgrade IBM Langflow OSS to version 1.9.2. Instructions for upgrading can be found on the Langflow OSS page on the Python Package Index (PyPI).

Added: May 28, 2026, 5:06 AM
Updated: May 28, 2026, 5:06 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.