Vulnerability  ·  2026-06-24

Langflow Unauthenticated Unbounded File Upload Causes Indefinite Denial of Service

VulnerabilityHigh impactGlobalCVE-2026-55450
Prior to Langflow 1.9.1, unauthenticated users can upload unlimited data to the server via the file upload endpoint with no size or rate limits. This can exhaust disk space on the server, rendering Langflow unusable for all users indefinitely. CVSS 9.3 Critical, published 2026-06-23.
A no-auth DoS against a production AI workflow platform disrupts all running agent pipelines and AI deployments on the instance. Attackers can trivially take down shared Langflow infrastructure used by multiple teams, causing cascading failures in automated AI processes that depend on Langflow flows.
Unauthenticated repeated file upload requests to Langflow's upload endpoint with large files; no server-side size limit or authentication check exhausts disk space
Langflow < 1.9.1
Upgrade to Langflow 1.9.1. PR fix: https://github.com/langflow-ai/langflow/pull/12831
Sources
NVD CVE-2026-55450Langflow PR #12831Meterian CVE-2026-55450 listing (confirmed description)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →