CVE-2026-3340: Server-Side Request Forgery (SSRF) in Langflow URL Component
IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3340?
CVE-2026-3340 has a high severity rating due to its potential to allow unauthorized requests and network enumeration.
How do I fix CVE-2026-3340?
To fix CVE-2026-3340, update IBM Langflow Desktop to the latest version beyond 1.8.4.
Who is affected by CVE-2026-3340?
CVE-2026-3340 affects all versions of IBM Langflow Desktop from 1.0.0 to 1.8.4.
What type of vulnerability is CVE-2026-3340?
CVE-2026-3340 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
What impact does CVE-2026-3340 have?
The impact of CVE-2026-3340 includes potential unauthorized access to local and remote resources, leading to security breaches.