Junglewise Threat Intelligence

CVE-2026-10546: IBM Langflow OSS SSRF in URL component via DNS rebinding

CVE-2026-10546 · Severity: high · CVSS 7.1 · Published 2026-06-30

Technologies: IBM Langflow OSS. Vendors: IBM.

Executive brief

IBM Langflow OSS, an open-source tool for building AI applications, is vulnerable to a security flaw in its URL data source component. An attacker could bypass security checks to force the application to make unauthorized requests to internal systems or private data that should be inaccessible. This could lead to the exposure of sensitive internal information or allow an attacker to probe the organization's private network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Langflow OSS versions 1.0.0 through 1.9.3 within the URL component (src/lfx/src/lfx/components/data_source/url.py). The vulnerability is caused by a Time-of-Check/Time-of-Use (TOCTOU) race condition where the application validates a URL using validate_url_for_ssrf() but subsequently fetches the content using RecursiveUrlLoader, which performs an independent DNS resolution. An attacker can exploit this via DNS rebinding to bypass SSRF protections and access internal network resources. While similar issues in other components were previously patched using IP pinning, this specific component remained vulnerable. The issue is resolved in Langflow OSS version 1.10.0.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.9.3

Timeline

  • 2026-06-23: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date
  • 2026-06-23: patched: IBM recommends upgrading to version 1.10.0

References

Related threats