CVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
References
Link Resource
https://www.ibm.com/support/pages/node/7278443 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:15

Type Values Removed Values Added
CPE cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
First Time Langflow langflow
Langflow
References () https://www.ibm.com/support/pages/node/7278443 - () https://www.ibm.com/support/pages/node/7278443 - Vendor Advisory

30 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 20:17

Updated : 2026-07-02 19:15


NVD link : CVE-2026-7871

Mitre link : CVE-2026-7871

CVE.ORG link : CVE-2026-7871


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-502

Deserialization of Untrusted Data