IBM Langflow OSS Weak Crypto Key Derivation in ensure_fernet_key()
CVE-2026-9205 Published on August 5, 2026
Langflow is affected by weaknesses in secret handling and sensitive configuration access
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
Vulnerability Analysis
CVE-2026-9205 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a PRNG Vulnerability?
The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
CVE-2026-9205 has been classified to as a PRNG vulnerability or weakness.
Products Associated with CVE-2026-9205
Want to know whenever a new CVE is published for IBM Langflow Oss? stack.watch will email you.
Affected Versions
IBM Langflow OSS:- Version 1.0.0, <= 1.10.3 is affected.