CVE Tools

Langflow

137 CVEs tracked since 2026. Since Jan 2026, 1 of them reached CISA KEV.

Langflow CVEs per month

Jan 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Langflow CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0160
2026-02null or fewer
2026-03111
2026-0480
2026-05null or fewer
2026-06250
2026-07180
2026-08340
2026-09350

Products

The products that kept showing up in Langflow's monthly top three, with their CVEs summed over those months.

  1. Langflow1307 months
  2. Langflow Desktop72 months
  3. Langflow-base11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Langflow.

  1. CVE-2026-76059Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  2. CVE-2026-78569Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  3. CVE-2026-78571Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  4. CVE-2026-78575Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  5. CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches5.0
  6. CVE-2026-79724Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards9.8
  7. CVE-2026-79725Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation6.5
  8. CVE-2026-79742Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  9. CVE-2026-81204Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards9.8
  10. CVE-2026-81211Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  11. CVE-2026-81941Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  12. CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches8.6
  13. CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches7.5
  14. CVE-2026-81268Langflow is vulnerable to authentication bypass and insufficient session expiration8.1
  15. CVE-2026-81940Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8

The record

Peak rank
#29 in Sep 2026
Busiest month shown
Sep 2026, 35 CVEs
Months with a KEV entry
1 since Jan 2026
Monthly snapshots
7 since 2026
Langflow's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store