IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7278209 | Vendor Advisory |
Configurations
History
02 Jul 2026, 16:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7278209 - Vendor Advisory | |
| First Time |
Langflow langflow
Langflow |
|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
30 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 20:17
Updated : 2026-07-02 16:43
NVD link : CVE-2026-10140
Mitre link : CVE-2026-10140
CVE.ORG link : CVE-2026-10140
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
