{"id":"GHSA-9pw3-x84f-xcwf","title":"Duplicate Advisory: Langflow: Weak Fernet Key via random.seed()","summary":"Duplicate Advisory: Langflow: Weak Fernet Key via random.seed()","severity":"high","cvss":7.4,"cwe":["CWE-338"],"vendor":"langflow","product":"langflow","ecosystem":"pip","affected":["langflow <= 1.10.0"],"published":"2026-08-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T22:31:33Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9pw3-x84f-xcwf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9205"},{"url":"https://www.ibm.com/support/pages/node/7282648"},{"url":"https://github.com/langflow-ai/langflow/pull/13704"},{"url":"https://github.com/langflow-ai/langflow/commit/094694d3f20c1da499f4d8dbac15c510609e3026"},{"url":"https://github.com/advisories/GHSA-9pw3-x84f-xcwf"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-05T22:35:24.745Z","slug":"GHSA-9pw3-x84f-xcwf","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-jxw3-mjmx-3pqm. This link is maintained to preserve external references.\n\n## Original Description\nIBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.\n\n## Affected packages\n\n- `langflow <= 1.10.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}