{"data":{"id":"741ba8ec-e95a-4cf3-812e-14876bf07b89","title":"CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's","summary":"IBM Langflow OSS versions 1.0.0 through 1.10.3 use Python's non-cryptographic random module (a weak randomness generator not designed for security) to create Fernet encryption keys (a cryptographic method for protecting data) from user secrets under 32 characters. Because the Mersenne Twister PRNG (pseudorandom number generator, an algorithm that produces predictable sequences) produces identical keys from identical seeds, attackers can recreate these keys and decrypt stored API keys and authentication tokens.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8470","publishedAt":"2026-08-05T19:17:44.823Z","cveId":"CVE-2026-8470","cweIds":["CWE-327"],"cvssScore":"7.4","cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-05T19:17:44.823Z","capecIds":["CAPEC-20"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}