Langflow vulnerabilities: known CVEs & security history
Langflow · Actively exploited · 123 tracked CVEs · 5 actively exploited · updated September 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Langflow release lines — 123 in total, with 5 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Langflow's current status and the safe version to run.
Known Langflow CVEs
Actively-exploited and most-severe first. Showing the top 80 of 123. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2026-9198⚡ exploited | critical | 9.8 | 17% | 2026 |
| CVE-2026-0770⚡ exploited | critical | 9.8 | 10% | 2026 |
| CVE-2025-3248⚡ exploited | critical | 9.8 | 100% | 2025 |
| CVE-2025-34291⚡ exploited | high | 8.8 | 79% | 2025 |
| CVE-2026-55255⚡ exploited | high | 8.4 | 0% | 2026 |
| CVE-2026-10134 | critical | 10 | 0% | 2026 |
| CVE-2026-10561 | critical | 10 | 1% | 2026 |
| CVE-2026-19295 | critical | 9.9 | 1% | 2026 |
| CVE-2026-12946 | critical | 9.9 | 0% | 2026 |
| CVE-2026-13435 | critical | 9.9 | 0% | 2026 |
| CVE-2026-8859 | critical | 9.9 | 0% | 2026 |
| CVE-2026-8635 | critical | 9.9 | 0% | 2026 |
| CVE-2026-8481 | critical | 9.9 | 0% | 2026 |
| CVE-2026-8476 | critical | 9.9 | 0% | 2026 |
| CVE-2026-9135 | critical | 9.9 | 1% | 2026 |
| CVE-2026-7873 | critical | 9.9 | 0% | 2026 |
| CVE-2026-81204 | critical | 9.8 | 1% | 2026 |
| CVE-2026-79724 | critical | 9.8 | 0% | 2026 |
| CVE-2026-85025 | critical | 9.8 | 0% | 2026 |
| CVE-2026-19286 | critical | 9.8 | 1% | 2026 |
| CVE-2026-12940 | critical | 9.8 | 0% | 2026 |
| CVE-2026-13446 | critical | 9.8 | 0% | 2026 |
| CVE-2026-8505 | critical | 9.8 | 1% | 2026 |
| CVE-2026-9103 | critical | 9.8 | 0% | 2026 |
| CVE-2026-9202 | critical | 9.8 | 0% | 2026 |
| CVE-2026-7871 | critical | 9.8 | 0% | 2026 |
| CVE-2026-7803 | critical | 9.8 | 0% | 2026 |
| CVE-2026-7664 | critical | 9.8 | 0% | 2026 |
| CVE-2026-10140 | critical | 9.6 | 0% | 2026 |
| CVE-2026-55447 | critical | 9.6 | 0% | 2026 |
| CVE-2026-48519 | critical | 9.6 | 1% | 2026 |
| CVE-2026-55450 | critical | 9.3 | 0% | 2026 |
| CVE-2026-19297 | critical | 9.1 | 0% | 2026 |
| CVE-2026-7874 | critical | 9.1 | 0% | 2026 |
| CVE-2026-7663 | critical | 9.1 | 0% | 2026 |
| CVE-2026-84889 | high | 8.8 | 1% | 2026 |
| CVE-2026-81941 | high | 8.8 | 1% | 2026 |
| CVE-2026-81940 | high | 8.8 | 1% | 2026 |
| CVE-2026-81211 | high | 8.8 | 0% | 2026 |
| CVE-2026-79742 | high | 8.8 | 1% | 2026 |
| CVE-2026-78575 | high | 8.8 | 1% | 2026 |
| CVE-2026-78571 | high | 8.8 | 1% | 2026 |
| CVE-2026-78569 | high | 8.8 | 0% | 2026 |
| CVE-2026-76059 | high | 8.8 | 0% | 2026 |
| CVE-2026-19298 | high | 8.8 | 0% | 2026 |
| CVE-2026-18729 | high | 8.8 | 0% | 2026 |
| CVE-2026-9201 | high | 8.8 | 0% | 2026 |
| CVE-2026-8478 | high | 8.8 | 0% | 2026 |
| CVE-2026-8182 | high | 8.8 | 0% | 2026 |
| CVE-2026-17632 | high | 8.8 | 0% | 2026 |
| CVE-2026-17626 | high | 8.8 | 0% | 2026 |
| CVE-2026-17623 | high | 8.8 | 1% | 2026 |
| CVE-2026-8056 | high | 8.8 | 0% | 2026 |
| CVE-2026-7755 | high | 8.8 | 0% | 2026 |
| CVE-2026-7667 | high | 8.8 | 0% | 2026 |
| CVE-2026-14499 | high | 8.8 | 0% | 2026 |
| CVE-2026-33760 | high | 8.8 | 0% | 2026 |
| CVE-2026-3357 | high | 8.8 | 0% | 2026 |
| CVE-2026-5027 | high | 8.8 | 31% | 2026 |
| CVE-2026-81213 | high | 8.6 | 0% | 2026 |
| CVE-2026-19305 | high | 8.6 | 0% | 2026 |
| CVE-2026-17633 | high | 8.5 | 0% | 2026 |
| CVE-2026-17624 | high | 8.5 | 0% | 2026 |
| CVE-2026-9077 | high | 8.5 | 0% | 2026 |
| CVE-2026-10129 | high | 8.5 | 0% | 2026 |
| CVE-2026-18904 | high | 8.2 | 0% | 2026 |
| CVE-2026-18891 | high | 8.2 | 0% | 2026 |
| CVE-2026-10564 | high | 8.2 | 0% | 2026 |
| CVE-2026-10560 | high | 8.2 | 0% | 2026 |
| CVE-2026-81268 | high | 8.1 | 0% | 2026 |
| CVE-2026-19303 | high | 8.1 | 0% | 2026 |
| CVE-2026-9196 | high | 8.1 | 0% | 2026 |
| CVE-2026-13444 | high | 8.1 | 0% | 2026 |
| CVE-2026-13445 | high | 8.1 | 0% | 2026 |
| CVE-2026-13448 | high | 8.1 | 0% | 2026 |
| CVE-2026-19306 | high | 7.7 | 0% | 2026 |
| CVE-2026-19304 | high | 7.7 | 0% | 2026 |
| CVE-2026-8183 | high | 7.7 | 0% | 2026 |
| CVE-2026-7754 | high | 7.7 | 0% | 2026 |
| CVE-2026-81265 | high | 7.5 | 0% | 2026 |
43 older / lower-severity CVEs not shown — see Langflow's full record.
Is my Langflow version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Langflow version → · Monitor Langflow for new CVEs →
Langflow vulnerabilities — frequently asked
How many known vulnerabilities does Langflow have?
IsItPatched tracks 123 CVEs for Langflow, 5 of which are actively exploited (CISA KEV). 33 are critical-severity and 63 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Langflow have any actively-exploited vulnerabilities?
Yes — 5 Langflow CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (1 linked to ransomware). Patch these as a priority.
What is the most severe Langflow vulnerability?
Among tracked issues, CVE-2026-9198 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Code injection weakness.
Is Langflow safe to use?
It depends on the version. The latest supported Langflow release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Langflow security status · Langflow end-of-life · actively-exploited CVEs. Always verify against Langflow's advisories — see our disclaimer.