CVE-2026-7528Disclosure(langflow / langflow)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-15: 1Mentions · 2026-07-01: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-15: 1Technical Details · 2026-07-01: 106-1507-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-151
Disclosure1
2026-07-011
Patch1
Full discourse2 posts
  • Ori@vbCrLf
    Disclosure

    Over the last few months, I researched Langflow, n8n, and Activepieces. The result is 9 zero-days and a BlueHat IL talk 🛠️ 🚨 CVE-2026-7524 (Critical - 9.8) 🚨 CVE-2026-48519 (Critical - 9.6) ⚠️ CVE-2026-7528 (High - 7.1) 🐛 CVE-2026-42228 (Moderate - 6.3) 🐛 CVE-2026-48520 (Moderate - 6.1) 🚨 CVE-not-yet-published (Critical - 9.0) 🚨 CVE-not-yet-published (Critical - 10.0) ⚠️ CVE-not-yet-published (High - 8.6) ⚠️ CVE-not-yet-published (High - 8.3) Thanks to the vendors for the cooperation and fixes. @Oranav and I will be breaking down some of these on stage at BlueHat IL 2026 Registration closes soon. Write-ups will be published after the con. Abstract: https://www.microsoftrnd.co.il/bluehatil/conference/abstracts#collapse-25 @BlueHatIL @msftsecresponse

    Post summary

    The post announces the discovery of nine zero‑day CVEs, lists their severity, thanks vendors for fixes, and notes that write‑ups will be released after a BlueHat IL presentation.

    11030468
    43 followersView on X
  • Rubrik Zero Labs@RubrikZeroLabs
    Patch

    Two more: CVE-2026-48520 (CVSS 6.1) and CVE-2026-7528 (CVSS 7.1). All four disclosed and patched Feb–May 2026.

    Post summary

    Four CVEs were disclosed and patched between February–May 2026 with CVSS scores noted, but no detailed technical or exploitation information is provided.

    1001065
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more