CVE Tools

Langflow

160 CVEs tracked. 6 of them are in CISA KEV.

This hub aggregates every CVE we track for Langflow, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Langflow CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Langflow CVEs per month
MonthCVEs
2024-101
2024-111
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-123
2026-016
2026-021
2026-0312
2026-047
2026-055
2026-0624
2026-0726
2026-0834
2026-0935

Severity

How the 160 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical4629%
  • High7648%
  • Medium3522%
  • Low32%

Latest CVEs

The 15 most recently published vulnerabilities affecting Langflow.

  1. CVE-2026-76059Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  2. CVE-2026-78569Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  3. CVE-2026-78571Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  4. CVE-2026-78575Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  5. CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches5.0
  6. CVE-2026-79724Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards9.8
  7. CVE-2026-79725Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation6.5
  8. CVE-2026-79742Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  9. CVE-2026-81204Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards9.8
  10. CVE-2026-81211Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  11. CVE-2026-81941Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8
  12. CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches8.6
  13. CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches7.5
  14. CVE-2026-81268Langflow is vulnerable to authentication bypass and insufficient session expiration8.1
  15. CVE-2026-81940Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store