• PATCH AVAILABLE

CVE-2026-9205: weak key derivation in IBM Langflow OSS

An unauthenticated remote attacker can exploit a weak cryptographic key derivation in Langflow OSS to recover or weaken protection of secrets and cryptographic material. CVE-2026-9205 is a CWE-338 weakness in the ensure_fernet_key() function that undermines key strength. Versions 1.0.0 through 1.10.3 of Langflow OSS are affected. The flaw is exploitable over the network without credentials or user interaction, giving attackers remote capability to affect confidentiality, integrity, and availability.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00417
CWE
CWE-338
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

High urgency: the weakness lets remote, unauthenticated attackers attack cryptographic keys (no login required), so immediately restrict external exposure and follow vendor guidance for updates or mitigations.

What is CVE-2026-9205?

An unauthenticated remote attacker can exploit a weak cryptographic key derivation in Langflow OSS to recover or weaken protection of secrets and cryptographic material. CVE-2026-9205 is a CWE-338 weakness in the ensure_fernet_key() function that undermines key strength. Versions 1.0.0 through 1.10.3 of Langflow OSS are affected. The flaw is exploitable over the network without credentials or user interaction, giving attackers remote capability to affect confidentiality, integrity, and availability. The weakness is classified as CWE-338 (Weak PRNG).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.10.3

Is CVE-2026-9205 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-9205

  1. Follow the vendor's advisory and apply patches or updates as soon as they are released.
  2. Restrict network exposure of Langflow OSS instances to trusted networks and internal users only.
  3. Rotate any Fernet keys, API keys, or stored secrets used by Langflow OSS after applying fixes.
  4. Monitor logs and alerting for abnormal access or attempts to access cryptographic material.

Frequently asked questions

Is CVE-2026-9205 being actively exploited?

There are no public reports of active exploitation of CVE-2026-9205 as of 2026-09-29.

Which Langflow OSS versions are affected by CVE-2026-9205?

Langflow OSS versions 1.0.0 through 1.10.3 are listed as affected by CVE-2026-9205.

Is there a patch for CVE-2026-9205?

The vendor indicates a patch is available in principle; fixed version numbers are not listed in the provided facts, so apply the vendor's guidance or updates when published.

Does CVE-2026-9205 require authentication?

No; the vulnerability can be exploited remotely without authentication against Langflow OSS.

References