IBM Langflow OSS 1.0.0 — CVE-2026-10140 (Critical)

Date Jun 30, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product IBM · Langflow OSS 1.0.0
CVE CVE-2026-10140
Critical vendor advisory CVE-2026-10140

Summary

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.6) in IBM Langflow OSS 1.0.0. Patch or mitigate promptly.

Operator check

Review CVE-2026-10140 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.6.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.