CVE-2026-7874
Critical · CVSS 9.1IBM Langflow OSS — Weak and reversible key derivation mechanism leading to credential disclosure (CWE-338)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-338
Description
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.
Search profile — drives PoC discovery
Symbols key derivationencryption at restcredential storagereversible encryptionKDFdecryptstored credentialssecret keyencryptfernetcryptography
Keywords CVE-2026-7874IBM Langflow OSSLangflow credential disclosureLangflow weak key derivationLangflow encryption at restLangflow reversible encryptionLangflow stored credentialsLangflow CWE-338Langflow decrypt credentialsLangflow 1.0.0 1.10.0 vulnerability
Versions: 1.0.0 through 1.10.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z