{"data":{"id":"b0473977-f378-4d0e-b2ac-2ce4d288d4e7","title":"GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)","summary":"Before Langflow 1.10.3, several built-in components, including RSS Reader, SearXNG, Web Search, Home Assistant, Glean Search and Docling Serve, sent server-side requests to flow-author-controlled URLs with no SSRF enforcement. An authenticated user who can build or run flows could reach loopback, private, link-local and cloud metadata addresses and often read the response back through the component output.","solution":"Fixed in Langflow 1.10.3 (and 1.11.0+), with patched versions langflow 1.10.3, langflow-base 0.10.3, lfx 1.10.3 and lfx-docling 0.1.2. With default settings, outbound requests from these components are now validated after DNS resolution, pinned to the validated IP, and blocked for private, loopback, link-local or metadata addresses unless the operator allowlists the host.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-j8f7-x8jm-wmm4","publishedAt":"2026-10-06T13:39:57.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["lfx-docling@< 0.1.2 (fixed: 0.1.2)","lfx@< 1.10.3 (fixed: 1.10.3)","langflow-base@< 0.10.3 (fixed: 0.10.3)","langflow@< 1.10.3 (fixed: 1.10.3)"],"affectedPackageNames":["lfx-docling","lfx","langflow-base","langflow"],"affectedPackageRefs":["pypi:langflow","pypi:langflow-base","pypi:lfx","pypi:lfx-docling"],"affectedVendors":[],"affectedVendorsRaw":["Langflow","API Request component","RSS Reader","SearXNG","Web Search","Home Assistant","Glean Search","Docling Serve"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-j8f7-x8jm-wmm4"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-06T13:39:57.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}