IBM Langflow OSS 1.0.0 — CVE-2026-10140 (Critical)
Critical vendor advisory
CVE-2026-10140
Summary
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.6) in IBM Langflow OSS 1.0.0. Patch or mitigate promptly.
Operator check
Review CVE-2026-10140 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.6.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.