CRITICAL 9.1 GitHub
CVE-2026-9205
Langflow: Weak Fernet Key via random.seed()
### Summary
Langflow uses Python's `random` module (Mersenne Twister, a non-cryptographic PRNG) seeded with the `SECRET_KEY` to derive the Fernet encryption key for all stored user credentials (API keys, LLM provider secrets, database passwords). When the `SECRET_KEY` is shorter than 32 characters — a common scenario for self-hosted deployments using simple/memorable secrets — the derived encryption key is fully deterministic and reproducible by anyone who knows the seed value. An attacker who
Affected Products
- pip/langflow <= 1.10.0
References
- https://github.com/advisories/GHSA-jxw3-mjmx-3pqm
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-jxw3-mjmx-3pqm
- https://nvd.nist.gov/vuln/detail/CVE-2026-9205
- https://github.com/langflow-ai/langflow/pull/13704
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-10-05 via GitHub. Affected: pip/langflow <= 1.10.0.
Risk Timeline
CVE Disclosed2026-10-05 · 0 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-9205Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-8505 | Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass | CRITICAL | 9.8 |
| CVE-2026-102268 | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public ke | CRITICAL | 9.1 |
| CVE-2026-51886 | Langflow: Title Authenticated Remote Code Execution in validate_code via Malic | HIGH | 8.8 |
| CVE-2026-7700 | Langflow: Prompt injection in Langflow Smart Transform can lead to code executio | HIGH | 8.8 |
| CVE-2026-71416 | Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) | HIGH | 8.8 |
| CVE-2026-87817 | GitPython: Repository content can impersonate the git directory, leading to arbi | HIGH | 8.8 |
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.