NPM · JUNE 2026 · CONFIRMED

Critical IBM Langflow OSS Vulnerability: Upgrade or Restrict Redis Access

CVE-2026-7871CVE-2026-7873cve-2026-7871Severity: CRITICAL

A confirmed critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.

What happened

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical vulnerability tracked as CVE-2026-7871 and CVE-2026-7873 that allows users with Redis access to execute arbitrary code with full application privileges. This compromises all secrets, data, and system integrity. The vulnerability has been confirmed by multiple independent sources and is rated as CRITICAL with CVSS scores ranging from 9.8 to 10.0.

The vulnerability arises from improper authorization enforcement and shared-state handling in the IBM Langflow OSS software. An attacker with Redis access can manipulate cache state and API clients to execute arbitrary code, access protected resources, and cause cross-tenant billing and accountability misattribution.

To assess your exposure, check if you are running IBM Langflow OSS versions 1.0.0 through 1.10.0 and if any users have Redis access. The recommended actions are to upgrade to a version beyond 1.10.0 or restrict Redis access to trusted users only. For more details, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats