Junglewise Threat Intelligence

CVE-2026-10564: IBM Langflow OSS SSRF in RSSReader and SearXNG components

CVE-2026-10564 · Severity: high · CVSS 8.2 · Published 2026-06-30

Technologies: IBM Langflow OSS. Vendors: IBM.

Executive brief

IBM Langflow OSS, a tool used to build AI-driven workflows, contains a security flaw in its RSS Reader and SearXNG components. This vulnerability allows an attacker to force the application to make unauthorized requests to internal systems, such as cloud metadata services. If exploited, this could lead to the theft of sensitive cloud credentials (like AWS or Azure IAM tokens) or the mapping of private internal networks, potentially resulting in a full cloud account takeover.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in IBM Langflow OSS versions 1.0.0 through 1.9.6. The root cause is located in the legacy RSSReaderComponent (rss.py) and SearXNG component (searxng.py), which fail to use the 'validate_url_for_ssrf()' check, instead calling 'requests.get()' directly on user-supplied URLs. This flaw bypasses SSRF protections introduced in version 1.9.3. An attacker can trigger this via direct API calls or through prompt injection in agentic workflows where 'tool_mode=True' is enabled. Successful exploitation allows for the exfiltration of cloud instance metadata (IMDS) credentials and internal network enumeration. The issue is resolved in version 1.10.0.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.9.6

Timeline

  • 2026-06-25: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date
  • 2026-06-30: patched: Upgrade to version 1.10.0 recommended

References

Related threats