LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-8470

langflow · langflow

Published
CVSS7.4
Severityhigh
WeaknessCWE-327
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-8470

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-8470.