Filtered by vendor Ibm
Subscriptions
Total
8487 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-9196 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-07 | 8.1 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process. | ||||
| CVE-2026-9205 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-07 | 7.4 High |
| IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | ||||
| CVE-2026-17630 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-07 | 7.2 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters. | ||||
| CVE-2026-9130 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-07 | 7.1 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False. | ||||
| CVE-2026-17617 | 1 Ibm | 2 Application Gateway, Application Gateway Operator | 2026-08-07 | 8.5 High |
| IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | ||||
| CVE-2026-15325 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-08-06 | 8.7 High |
| IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. | ||||
| CVE-2026-11714 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-08-06 | 8.5 High |
| IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | ||||
| CVE-2026-7869 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-06 | 5.4 Medium |
| IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. | ||||
| CVE-2026-10128 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-06 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. | ||||
| CVE-2026-18531 | 1 Ibm | 1 Maximo Application Suite | 2026-08-06 | 5.3 Medium |
| IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | ||||
| CVE-2026-10025 | 1 Ibm | 2 Qradar, Qradar Security Information And Event Manager | 2026-08-06 | 8.2 High |
| IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. | ||||
| CVE-2026-8400 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-08-06 | 8.1 High |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | ||||
| CVE-2026-7658 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation. | ||||
| CVE-2026-8182 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. | ||||
| CVE-2026-17633 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 8.5 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. | ||||
| CVE-2026-17624 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 8.5 High |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. | ||||
| CVE-2026-9201 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA‑256 hash. Because the hash comparison relies on only a portion of the digest, an attacker can craft malicious component code that collides with a trusted template hash and bypasses validation. Successful exploitation allows the attacker to introduce and execute unauthorized Python code within the Langflow process, defeating the intended security control and potentially leading to full compromise of the affected instance. | ||||
| CVE-2026-17632 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. | ||||
| CVE-2026-8470 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 7.4 High |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens. | ||||
| CVE-2026-10547 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 5.9 Medium |
| IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service. | ||||