Back

CRITICAL

Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem

Published Jun 30, 2026

Description

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jun 30, 2026
Updated Aug 11, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Jul 1, 2026
NVD
Status Analyzed
Modified Aug 11, 2026
Red Hat
Severity n/a
Public date n/a