U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-9077 - IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
    Published: August 05, 2026; 1:16:57 PM -0400

  • CVE-2026-7658 - IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion,... read CVE-2026-7658
    Published: August 05, 2026; 3:17:43 PM -0400

  • CVE-2026-10128 - IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
    Published: August 05, 2026; 2:16:51 PM -0400

  • CVE-2026-7869 - IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitiz... read CVE-2026-7869
    Published: August 05, 2026; 3:17:43 PM -0400

  • CVE-2026-8182 - IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
    Published: August 05, 2026; 3:17:43 PM -0400

  • CVE-2026-8183 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a s... read CVE-2026-8183
    Published: August 05, 2026; 3:17:43 PM -0400

    V3.1: 7.7 HIGH

  • CVE-2026-8470 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic... read CVE-2026-8470
    Published: August 05, 2026; 3:17:44 PM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2026-8478 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
    Published: August 05, 2026; 3:17:45 PM -0400

  • CVE-2026-9130 - IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and st... read CVE-2026-9130
    Published: August 05, 2026; 3:17:46 PM -0400

  • CVE-2026-65432 - Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DO... read CVE-2026-65432
    Published: August 06, 2026; 7:16:30 AM -0400

  • CVE-2026-66909 - Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious s... read CVE-2026-66909
    Published: August 06, 2026; 7:16:30 AM -0400

  • CVE-2026-57818 - A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to ve... read CVE-2026-57818
    Published: August 06, 2026; 8:16:27 AM -0400

  • CVE-2026-61466 - In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead... read CVE-2026-61466
    Published: August 06, 2026; 8:16:27 AM -0400

  • CVE-2026-63687 - Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secr... read CVE-2026-63687
    Published: August 06, 2026; 8:16:27 AM -0400

  • CVE-2026-65583 - Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that ... read CVE-2026-65583
    Published: August 06, 2026; 8:16:27 AM -0400

  • CVE-2026-68079 - In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The aut... read CVE-2026-68079
    Published: August 06, 2026; 8:16:28 AM -0400

  • CVE-2026-68481 - In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization... read CVE-2026-68481
    Published: August 06, 2026; 8:16:28 AM -0400

  • CVE-2026-60023 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path w... read CVE-2026-60023
    Published: August 05, 2026; 12:16:58 PM -0400

  • CVE-2026-64958 - An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, whic... read CVE-2026-64958
    Published: August 06, 2026; 7:16:30 AM -0400

  • CVE-2026-57819 - Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with... read CVE-2026-57819
    Published: August 06, 2026; 7:16:30 AM -0400