Langflow, Server-Side Request Forgery (SSRF), CVE ID: Not Provided in Source (Critical) -DC-Oct2026-2749

Listen to this Post

Before Langflow 1.10.3, built-in components sent server-side HTTP requests to flow-author-controlled URLs.

No SSRF enforcement existed for these component requests.

An authenticated user who could build or run flows could force the Langflow server to make outbound requests.

Those requests could reach loopback addresses.

They could reach RFC 1918 private networks.

They could reach link-local addresses.

They could reach cloud metadata endpoints.

One example endpoint was http://169.254.169.254/latest/meta-data/.
In many cases the component output returned the response.

Two flaws combined to cause this.

First, the SSRF guard was disabled or warn-only.

The guard lived in lfx/utils/ssrf_protection.py.

It was added in 1.7.0 by PR 10544.

It shipped with ssrf_protection_enabled = False.

Its only caller was the API Request component.

That caller used validate_url_for_ssrf(url, warn_only=True).

Even with protection turned on, blocked URLs were only logged.

Second, coverage was inconsistent.

Other URL-taking components did not call the guard at all.

Those components included RSS Reader.

They included SearXNG.

They included Web Search while fetching result or RSS URLs.

They included Home Assistant.

They included Glean Search.

They included Docling Serve remote.

The issue was fixed across several PRs.

It is fully fixed in Langflow 1.10.3.

It is also fixed in 1.11.0 and later.

Default settings now validate outbound requests after DNS resolution.

Requests are pinned to the validated IP.

This prevents DNS rebinding.

Private, loopback, link-local, and metadata addresses are blocked unless allowlisted.

Operators can use LANGFLOW_SSRF_ALLOWED_HOSTS.

Operators can use LANGFLOW_CONNECTOR_SSRF_VALIDATION_ENABLED.

DailyCVE Form:

Platform: Langflow
Version: < 1.10.3
Vulnerability : SSRF
Severity: Critical
date: Not provided

Prediction: Fixed in 1.10.3

(end of form)

What Undercode Say:

Analytics:

python -c "import langflow; print(langflow.<strong>version</strong>)"
pip show langflow langflow-base lfx lfx-docling
grep -R "ssrf_protection_enabled" -n .
grep -R "validate_url_for_ssrf" -n .
grep -R "ssrf_safe_get" -n .
grep -R "ssrf_safe_httpx_get" -n .
grep -R "ssrf_protected_httpx_client_kwargs_for_url" -n .
vulnerable rss.py before 13395
response = requests.get(self.rss_url, timeout=self.timeout)
API Request before 13016
validate_url_for_ssrf(url, warn_only=True)
with ssrf_protection_enabled: bool = False
patched
ssrf_protection_enabled: bool = True
response = ssrf_safe_get(self.rss_url, timeout=self.timeout)
ssrf_safe_httpx_get(...)
ssrf_protected_httpx_client_kwargs_for_url(base_url)

Exploit: (Educational Purposes!)

Log in as any user who can create flows.
Add RSS Reader (or SearXNG / Home Assistant / Glean / Docling Serve).
Set URL to http://169.254.169.254/latest/meta-data/.
Or set URL to http://10.0.0.1/.
Run the component.
Langflow server issues the request.
Response or error is shown in component output.
Patched versions fail with:
SSRFProtectionError: Access to IP address 169.254.169.254 is blocked by SSRF protection.

Protection: from this CVE

pip install "langflow>=1.10.3"
pip install "langflow-base>=0.10.3"
pip install "lfx>=1.10.3"
pip install "lfx-docling>=0.1.2"
export LANGFLOW_SSRF_PROTECTION_ENABLED=true
export LANGFLOW_SSRF_ALLOWED_HOSTS="internal.example.com"
export LANGFLOW_CONNECTOR_SSRF_VALIDATION_ENABLED=true
iptables -A OUTPUT -d 169.254.169.254 -j DROP

Impact:

  • Access to cloud instance metadata (IAM credentials / tokens) on AWS, GCP and Azure deployments.
  • Probing and interaction with internal services and private networks reachable from the Langflow host.
  • Requires an authenticated account with permission to build or run flows.
  • Deployments where every user is already fully trusted are less affected.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top