Vulnerability record · CVE-2026-55446 · published 23 June 2026
CVE-2026-55446: Langflow uncontrolled resource consumption vulnerability
Langflow · Langflow
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19.
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time. This vulnerability is fixed in 1.0.19.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/langflow-ai/langflow/pull/3923 | Issue TrackingPatch |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9 | ExploitPatchVendor Advisory |
| https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9 | ExploitPatchVendor Advisory |
Track CVE-2026-55446 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-55446), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.