langflow-base vulnerabilities
CVEs whose affected-version data names the langflow-base package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-6596High· 7.3Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
▾ Twilightlangflow-base · langflow-baseEPSS 0.28%via OSV
CVE-2026-34046HighLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
▾ Twilightlangflow · langflowEPSS 0.47%via OSV
CVE-2026-21445HighPoCLangflow Missing Authentication on Critical API Endpoints
Langflow Missing Authentication on Critical API Endpoints
▾ Midnightlangflow-base · langflow-baseEPSS 34%via OSV
CVE-2025-57760High· 8.8Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
▾ Twilightlangflow · langflowEPSS 0.48%via OSV