CVE-2026-55446 Details
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19.
A denial-of-service vulnerability has been identified in Langflow versions prior to 1.0.19. The issue arises in the file upload API, where an attacker can send a request without authentication tokens or cookies. By exploiting a very long multipart form boundary, the attacker can disrupt the Langflow application, causing it to become unresponsive for all users for an indefinite period. This vulnerability is particularly concerning because it can be repeated multiple times, prolonging the disruption.
Users are advised to upgrade to Langflow version 1.0.19 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9 | CISA-ADP | ExploitPatchVendor Advisory |
| https://github.com/langflow-ai/langflow/pull/3923 | [email protected] | Issue TrackingPatch |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9 | [email protected] | ExploitPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| langflow langflow | < 1.0.19 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |