CVE-2026-8470

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
References
Link Resource
https://www.ibm.com/support/pages/node/7282648 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 19:17

Updated : 2026-08-06 18:52


NVD link : CVE-2026-8470

Mitre link : CVE-2026-8470

CVE.ORG link : CVE-2026-8470


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm