IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7282648 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-05 19:17
Updated : 2026-08-06 18:52
NVD link : CVE-2026-8470
Mitre link : CVE-2026-8470
CVE.ORG link : CVE-2026-8470
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
