IBM Langflow OSS Weak Crypto Key Derivation in ensure_fernet_key()
CVE-2026-9205 Published on August 5, 2026

Langflow is affected by weaknesses in secret handling and sensitive configuration access
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-9205 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is a PRNG Vulnerability?

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

CVE-2026-9205 has been classified to as a PRNG vulnerability or weakness.


Products Associated with CVE-2026-9205

Want to know whenever a new CVE is published for IBM Langflow Oss? stack.watch will email you.

 

Affected Versions

IBM Langflow OSS: