CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
highvulnerability
security
Summary
IBM Langflow OSS (an open-source software tool) has a weak cryptographic key derivation vulnerability in its ensure_fernet_key() function (a function that creates encryption keys using Fernet, a symmetric encryption method). The issue involves using a cryptographically weak pseudo-random number generator (PRNG, a tool for creating unpredictable numbers needed for secure encryption), which could compromise the strength of generated encryption keys.
Vulnerability Details
CVSS Score
7.4(high)
EPSS (30-day exploit probability)
EPSS: 0.2%
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
network
Attack Complexity
high
Privileges Required
none
User Interaction
none
Disclosure Date
August 5, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
confidentialityintegrity
AI Component TargetedFramework
Taxonomy References
CWE (Weakness Type)
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9205
First tracked: August 6, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%