IBM disclosed CVE-2026-19297, a critical authentication weakness in Langflow OSS that allows unlimited login attempts when rate limiting on the POST /api/v1/login endpoint is disabled. The issue maps to CWE-307 (Improper Restriction of Excessive Authentication Attempts) and affects Langflow OSS versions 1.0.0 through 1.9.6. IBM assigned the flaw a CVSS 3.1 score of 9.1, warning that attackers with network access could conduct brute-force or credential-stuffing attacks against exposed instances.
Successful exploitation could compromise user accounts and potentially lead to superuser-level access. IBM said the weakness stems from the LANGFLOW_RATE_LIMIT_ENABLED environment variable, which can disable brute-force protections if not properly validated after deployment. The company recommended upgrading to Langflow OSS 1.10.0 or later and said no workaround or alternative mitigation is available.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 12, 2026, IBM published a security bulletin for CVE-2026-19297, describing insufficient authentication brute-force protection on Langflow OSS's POST /api/v1/login endpoint. IBM assigned the issue a CVSS 3.1 score of 9.1, mapped it to CWE-307, and said no workaround or mitigation is available.
IBM states that Langflow OSS versions 1.0.0 through 1.9.6 are affected and recommends upgrading to version 1.10.0 or newer to remediate the brute-force protection flaw on the login endpoint. A PyPI reference shows Langflow 1.10.0 was published on August 4, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
ibm.com
Open sourcepypi.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.