Executive brief
IBM Langflow OSS is a low-code platform for building AI applications and workflows. Due to insufficient rate limiting on the login endpoint, an attacker can submit unlimited credential guesses at network speed, enabling brute force or credential stuffing attacks against user accounts. If successful, an attacker could gain full access to the system including superuser privileges, compromising both data and operations.
Technical details
The vulnerability is an improper restriction of excessive authentication attempts (CWE-307) in the login endpoint (POST /api/v1/login). Rate limiting is controlled via the LANGFLOW_RATE_LIMIT_ENABLED environment variable, which defaults to enabled with a 5 attempts per minute per IP limit using in-memory storage. However, when this control is explicitly disabled by an administrator or not validated post-deployment, an attacker with network access can perform unlimited brute force attacks at full speed against weak or default credentials. No authentication is required to reach the vulnerable endpoint. The fix is available in Langflow OSS 1.10.0 and newer.
Affected products
- IBM Langflow OSS 1.0.0 through 1.9.6
Timeline
- 2026-08-12: disclosed: IBM Security Bulletin published
- 2026: patched: Fixed in Langflow OSS 1.10.0 and newer