Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
Weak Cryptographic Key Derivation Exposed All Stored Credentials
CVE-2026-7874
Description
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278447mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.