{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-33484",
        "tracking": {
            "current_release_date": "2026-03-26T00:50:20.758381Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-33484",
            "initial_release_date": "2026-03-20T21:41:05.092629Z",
            "revision_history": [
                {
                    "date": "2026-03-20T21:41:05.092629Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T21:41:08.997905Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-23T13:46:33.022922Z",
                    "number": "3",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (2).| References created (5)."
                },
                {
                    "date": "2026-03-23T13:46:40.048315Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:48:43.832361Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:48:46.365471Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:49:40.412277Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T20:49:42.907702Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:53:32.214028Z",
                    "number": "9",
                    "summary": "Products created (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-24T20:53:34.939198Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:57:44.928116Z",
                    "number": "11",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-24T21:19:28.792833Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T21:50:15.493362Z",
                    "number": "13",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-25T21:50:17.224197Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T00:38:30.095325Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (65).| Product Identifiers created (65).| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-26T00:38:43.564006Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-26T00:50:17.754381Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-26T00:50:19.661486Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "18"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.7.0",
                                "product": {
                                    "name": "vers:unknown/<1.7.0",
                                    "product_id": "CSAFPID-5892271"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.9.0",
                                "product": {
                                    "name": "vers:unknown/<1.9.0",
                                    "product_id": "CSAFPID-5875108"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Langflow"
                    }
                ],
                "category": "vendor",
                "name": "Open Source"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.0.0|<1.9.0",
                                "product": {
                                    "name": "vers:unknown/>=1.0.0|<1.9.0",
                                    "product_id": "CSAFPID-5902769",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "langflow"
                    }
                ],
                "category": "vendor",
                "name": "langflow"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0",
                                "product": {
                                    "name": "vers:unknown/1.0.0",
                                    "product_id": "CSAFPID-3234919",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.1",
                                "product": {
                                    "name": "vers:unknown/1.0.1",
                                    "product_id": "CSAFPID-3234982",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.10",
                                "product": {
                                    "name": "vers:unknown/1.0.10",
                                    "product_id": "CSAFPID-3234983",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.11",
                                "product": {
                                    "name": "vers:unknown/1.0.11",
                                    "product_id": "CSAFPID-3234984",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.12",
                                "product": {
                                    "name": "vers:unknown/1.0.12",
                                    "product_id": "CSAFPID-3234985",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.12"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.13",
                                "product": {
                                    "name": "vers:unknown/1.0.13",
                                    "product_id": "CSAFPID-4774140",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.13"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.14",
                                "product": {
                                    "name": "vers:unknown/1.0.14",
                                    "product_id": "CSAFPID-4774141",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.14"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.15",
                                "product": {
                                    "name": "vers:unknown/1.0.15",
                                    "product_id": "CSAFPID-4774142",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.15"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.16",
                                "product": {
                                    "name": "vers:unknown/1.0.16",
                                    "product_id": "CSAFPID-4774143",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.16"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.17",
                                "product": {
                                    "name": "vers:unknown/1.0.17",
                                    "product_id": "CSAFPID-4774144",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.17"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.18",
                                "product": {
                                    "name": "vers:unknown/1.0.18",
                                    "product_id": "CSAFPID-4774145",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.18"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.19",
                                "product": {
                                    "name": "vers:unknown/1.0.19",
                                    "product_id": "CSAFPID-4774146",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.19"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.19.post1",
                                "product": {
                                    "name": "vers:unknown/1.0.19.post1",
                                    "product_id": "CSAFPID-4774147",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.19.post1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.19.post2",
                                "product": {
                                    "name": "vers:unknown/1.0.19.post2",
                                    "product_id": "CSAFPID-4774148",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.19.post2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.2",
                                "product": {
                                    "name": "vers:unknown/1.0.2",
                                    "product_id": "CSAFPID-3234986",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.3",
                                "product": {
                                    "name": "vers:unknown/1.0.3",
                                    "product_id": "CSAFPID-3234987",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.4",
                                "product": {
                                    "name": "vers:unknown/1.0.4",
                                    "product_id": "CSAFPID-3234988",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.5",
                                "product": {
                                    "name": "vers:unknown/1.0.5",
                                    "product_id": "CSAFPID-3234989",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.6",
                                "product": {
                                    "name": "vers:unknown/1.0.6",
                                    "product_id": "CSAFPID-3234990",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.7",
                                "product": {
                                    "name": "vers:unknown/1.0.7",
                                    "product_id": "CSAFPID-3234991",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.8",
                                "product": {
                                    "name": "vers:unknown/1.0.8",
                                    "product_id": "CSAFPID-3234992",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.9",
                                "product": {
                                    "name": "vers:unknown/1.0.9",
                                    "product_id": "CSAFPID-3234993",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.0.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.0",
                                "product": {
                                    "name": "vers:unknown/1.1.0",
                                    "product_id": "CSAFPID-4774149",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.1",
                                "product": {
                                    "name": "vers:unknown/1.1.1",
                                    "product_id": "CSAFPID-4774150",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.2",
                                "product": {
                                    "name": "vers:unknown/1.1.2",
                                    "product_id": "CSAFPID-3739206",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.3",
                                "product": {
                                    "name": "vers:unknown/1.1.3",
                                    "product_id": "CSAFPID-3739207",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.4",
                                "product": {
                                    "name": "vers:unknown/1.1.4",
                                    "product_id": "CSAFPID-3739208",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.4.post1",
                                "product": {
                                    "name": "vers:unknown/1.1.4.post1",
                                    "product_id": "CSAFPID-4774151",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.1.4.post1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.0",
                                "product": {
                                    "name": "vers:unknown/1.2.0",
                                    "product_id": "CSAFPID-3739209",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.0",
                                "product": {
                                    "name": "vers:unknown/1.3.0",
                                    "product_id": "CSAFPID-3739210",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.1",
                                "product": {
                                    "name": "vers:unknown/1.3.1",
                                    "product_id": "CSAFPID-3739211",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.3.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.2",
                                "product": {
                                    "name": "vers:unknown/1.3.2",
                                    "product_id": "CSAFPID-3739212",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.3.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.3",
                                "product": {
                                    "name": "vers:unknown/1.3.3",
                                    "product_id": "CSAFPID-3739213",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.3.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.4",
                                "product": {
                                    "name": "vers:unknown/1.3.4",
                                    "product_id": "CSAFPID-3739214",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.3.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.0",
                                "product": {
                                    "name": "vers:unknown/1.4.0",
                                    "product_id": "CSAFPID-3739215",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.1",
                                "product": {
                                    "name": "vers:unknown/1.4.1",
                                    "product_id": "CSAFPID-3739216",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.2",
                                "product": {
                                    "name": "vers:unknown/1.4.2",
                                    "product_id": "CSAFPID-3739217",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.4.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.3",
                                "product": {
                                    "name": "vers:unknown/1.4.3",
                                    "product_id": "CSAFPID-4818258",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.4.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.0",
                                "product": {
                                    "name": "vers:unknown/1.5.0",
                                    "product_id": "CSAFPID-4818259",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.0.post1",
                                "product": {
                                    "name": "vers:unknown/1.5.0.post1",
                                    "product_id": "CSAFPID-3739218",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.5.0.post1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.0.post2",
                                "product": {
                                    "name": "vers:unknown/1.5.0.post2",
                                    "product_id": "CSAFPID-5281259",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.5.0.post2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.1",
                                "product": {
                                    "name": "vers:unknown/1.5.1",
                                    "product_id": "CSAFPID-5288776",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.0",
                                "product": {
                                    "name": "vers:unknown/1.6.0",
                                    "product_id": "CSAFPID-5288777",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.1",
                                "product": {
                                    "name": "vers:unknown/1.6.1",
                                    "product_id": "CSAFPID-5288778",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.2",
                                "product": {
                                    "name": "vers:unknown/1.6.2",
                                    "product_id": "CSAFPID-5288779",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.3",
                                "product": {
                                    "name": "vers:unknown/1.6.3",
                                    "product_id": "CSAFPID-5288780",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.4",
                                "product": {
                                    "name": "vers:unknown/1.6.4",
                                    "product_id": "CSAFPID-5288781",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.5",
                                "product": {
                                    "name": "vers:unknown/1.6.5",
                                    "product_id": "CSAFPID-5288782",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.6",
                                "product": {
                                    "name": "vers:unknown/1.6.6",
                                    "product_id": "CSAFPID-5288783",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.7",
                                "product": {
                                    "name": "vers:unknown/1.6.7",
                                    "product_id": "CSAFPID-5288784",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.8",
                                "product": {
                                    "name": "vers:unknown/1.6.8",
                                    "product_id": "CSAFPID-5288785",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.9",
                                "product": {
                                    "name": "vers:unknown/1.6.9",
                                    "product_id": "CSAFPID-5288786",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.6.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.0",
                                "product": {
                                    "name": "vers:unknown/1.7.0",
                                    "product_id": "CSAFPID-5288787",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.7.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.1",
                                "product": {
                                    "name": "vers:unknown/1.7.1",
                                    "product_id": "CSAFPID-5446094",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.7.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.2",
                                "product": {
                                    "name": "vers:unknown/1.7.2",
                                    "product_id": "CSAFPID-5667815",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.7.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.3",
                                "product": {
                                    "name": "vers:unknown/1.7.3",
                                    "product_id": "CSAFPID-5667816",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.7.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0",
                                "product": {
                                    "name": "vers:unknown/1.8.0",
                                    "product_id": "CSAFPID-5907976",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc0",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc0",
                                    "product_id": "CSAFPID-5737696",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc1",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc1",
                                    "product_id": "CSAFPID-5737697",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc2",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc2",
                                    "product_id": "CSAFPID-5737698",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc3",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc3",
                                    "product_id": "CSAFPID-5907977",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc4",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc4",
                                    "product_id": "CSAFPID-5907978",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc5",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc5",
                                    "product_id": "CSAFPID-5907979",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0rc6",
                                "product": {
                                    "name": "vers:unknown/1.8.0rc6",
                                    "product_id": "CSAFPID-5907980",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.0rc6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.1",
                                "product": {
                                    "name": "vers:unknown/1.8.1",
                                    "product_id": "CSAFPID-5907981",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/langflow@1.8.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.0.0|<1.9.0",
                                "product": {
                                    "name": "vers:unknown/>=1.0.0|<1.9.0",
                                    "product_id": "CSAFPID-5902377"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.0.0|<=1.8.1",
                                "product": {
                                    "name": "vers:unknown/>=1.0.0|<=1.8.1",
                                    "product_id": "CSAFPID-5912906"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "langflow"
                    }
                ],
                "category": "vendor",
                "name": "langflow-ai"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-33484",
            "cwe": {
                "id": "CWE-639",
                "name": "Authorization Bypass Through User-Controlled Key"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "### Summary\nThe `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without any authentication or ownership check. Any unauthenticated request with a known flow_id and file_name returns the image with HTTP 200.\n\n### Details\n`src/backend/base/langflow/api/v1/files.py:138-164` — `download_image` takes `flow_id`: UUID as a bare path parameter with no Depends(get_flow) or `CurrentActiveUser`. All other file routes (`download_file`, `upload_file`, `list_files`, `delete_file`) use `Depends(get_flow)` which enforces both authentication and ownership. There is no global auth middleware on /api/v1; protection is per-endpoint only.\n\n### PoC\n```\ncurl -v \"http://localhost:7860/api/v1/files/images/<flow_uuid>/<filename.png>\"\n# Returns HTTP 200 with image bytes, no auth header required\n```\n\n### Impact\nUnauthenticated cross-tenant data leak. In a multi-tenant deployment, any attacker who can discover or guess a `flow_id` (UUIDs can be leaked through other API responses) can download any user's uploaded images without credentials.",
                    "title": "github - https://api.github.com/advisories/GHSA-7grx-3xcx-2xv5"
                },
                {
                    "category": "description",
                    "text": "Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without any authentication or ownership check. Any unauthenticated request with a known flow_id and file_name returns the image with HTTP 200. In a multi-tenant deployment, any attacker who can discover or guess a `flow_id` (UUIDs can be leaked through other API responses) can download any user's uploaded images without credentials. Version 1.9.0 contains a patch.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33484.json"
                },
                {
                    "category": "description",
                    "text": "Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without any authentication or ownership check. Any unauthenticated request with a known flow_id and file_name returns the image with HTTP 200. In a multi-tenant deployment, any attacker who can discover or guess a `flow_id` (UUIDs can be leaked through other API responses) can download any user's uploaded images without credentials. Version 1.9.0 contains a patch.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33484"
                },
                {
                    "category": "description",
                    "text": "### Summary\nThe `/api/v1/files/images/{flow_id}/{file_name}` endpoint serves image files without any authentication or ownership check. Any unauthenticated request with a known flow_id and file_name returns the image with HTTP 200.\n\n### Details\n`src/backend/base/langflow/api/v1/files.py:138-164` — `download_image` takes `flow_id`: UUID as a bare path parameter with no Depends(get_flow) or `CurrentActiveUser`. All other file routes (`download_file`, `upload_file`, `list_files`, `delete_file`) use `Depends(get_flow)` which enforces both authentication and ownership. There is no global auth middleware on /api/v1; protection is per-endpoint only.\n\n### PoC\n```\ncurl -v \"http://localhost:7860/api/v1/files/images/<flow_uuid>/<filename.png>\"\n# Returns HTTP 200 with image bytes, no auth header required\n```\n\n### Impact\nUnauthenticated cross-tenant data leak. In a multi-tenant deployment, any attacker who can discover or guess a `flow_id` (UUIDs can be leaked through other API responses) can download any user's uploaded images without credentials.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/PyPI%2FGHSA-7grx-3xcx-2xv5.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00017",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, The value of the most recent EPSS score, There is cwe data available from source Github, There is exploit data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5875108",
                    "CSAFPID-5892271",
                    "CSAFPID-5902377",
                    "CSAFPID-5902769",
                    "CSAFPID-3234919",
                    "CSAFPID-3234982",
                    "CSAFPID-3234983",
                    "CSAFPID-3234984",
                    "CSAFPID-3234985",
                    "CSAFPID-3234986",
                    "CSAFPID-3234987",
                    "CSAFPID-3234988",
                    "CSAFPID-3234989",
                    "CSAFPID-3234990",
                    "CSAFPID-3234991",
                    "CSAFPID-3234992",
                    "CSAFPID-3234993",
                    "CSAFPID-3739206",
                    "CSAFPID-3739207",
                    "CSAFPID-3739208",
                    "CSAFPID-3739209",
                    "CSAFPID-3739210",
                    "CSAFPID-3739211",
                    "CSAFPID-3739212",
                    "CSAFPID-3739213",
                    "CSAFPID-3739214",
                    "CSAFPID-3739215",
                    "CSAFPID-3739216",
                    "CSAFPID-3739217",
                    "CSAFPID-3739218",
                    "CSAFPID-4774140",
                    "CSAFPID-4774141",
                    "CSAFPID-4774142",
                    "CSAFPID-4774143",
                    "CSAFPID-4774144",
                    "CSAFPID-4774145",
                    "CSAFPID-4774146",
                    "CSAFPID-4774147",
                    "CSAFPID-4774148",
                    "CSAFPID-4774149",
                    "CSAFPID-4774150",
                    "CSAFPID-4774151",
                    "CSAFPID-4818258",
                    "CSAFPID-4818259",
                    "CSAFPID-5281259",
                    "CSAFPID-5288776",
                    "CSAFPID-5288777",
                    "CSAFPID-5288778",
                    "CSAFPID-5288779",
                    "CSAFPID-5288780",
                    "CSAFPID-5288781",
                    "CSAFPID-5288782",
                    "CSAFPID-5288783",
                    "CSAFPID-5288784",
                    "CSAFPID-5288785",
                    "CSAFPID-5288786",
                    "CSAFPID-5288787",
                    "CSAFPID-5446094",
                    "CSAFPID-5667815",
                    "CSAFPID-5667816",
                    "CSAFPID-5737696",
                    "CSAFPID-5737697",
                    "CSAFPID-5737698",
                    "CSAFPID-5907976",
                    "CSAFPID-5907977",
                    "CSAFPID-5907978",
                    "CSAFPID-5907979",
                    "CSAFPID-5907980",
                    "CSAFPID-5907981",
                    "CSAFPID-5912906"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-7grx-3xcx-2xv5"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0823.json"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33484.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33484"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/PyPI%2FGHSA-7grx-3xcx-2xv5.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-7grx-3xcx-2xv5"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-7grx-3xcx-2xv5"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0823.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0823"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-87cc-65ph-2j4w"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-ph9w-r52h-28p7"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33484"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-3234919",
                        "CSAFPID-3234982",
                        "CSAFPID-3234983",
                        "CSAFPID-3234984",
                        "CSAFPID-3234985",
                        "CSAFPID-3234986",
                        "CSAFPID-3234987",
                        "CSAFPID-3234988",
                        "CSAFPID-3234989",
                        "CSAFPID-3234990",
                        "CSAFPID-3234991",
                        "CSAFPID-3234992",
                        "CSAFPID-3234993",
                        "CSAFPID-3739206",
                        "CSAFPID-3739207",
                        "CSAFPID-3739208",
                        "CSAFPID-3739209",
                        "CSAFPID-3739210",
                        "CSAFPID-3739211",
                        "CSAFPID-3739212",
                        "CSAFPID-3739213",
                        "CSAFPID-3739214",
                        "CSAFPID-3739215",
                        "CSAFPID-3739216",
                        "CSAFPID-3739217",
                        "CSAFPID-3739218",
                        "CSAFPID-4774140",
                        "CSAFPID-4774141",
                        "CSAFPID-4774142",
                        "CSAFPID-4774143",
                        "CSAFPID-4774144",
                        "CSAFPID-4774145",
                        "CSAFPID-4774146",
                        "CSAFPID-4774147",
                        "CSAFPID-4774148",
                        "CSAFPID-4774149",
                        "CSAFPID-4774150",
                        "CSAFPID-4774151",
                        "CSAFPID-4818258",
                        "CSAFPID-4818259",
                        "CSAFPID-5281259",
                        "CSAFPID-5288776",
                        "CSAFPID-5288777",
                        "CSAFPID-5288778",
                        "CSAFPID-5288779",
                        "CSAFPID-5288780",
                        "CSAFPID-5288781",
                        "CSAFPID-5288782",
                        "CSAFPID-5288783",
                        "CSAFPID-5288784",
                        "CSAFPID-5288785",
                        "CSAFPID-5288786",
                        "CSAFPID-5288787",
                        "CSAFPID-5446094",
                        "CSAFPID-5667815",
                        "CSAFPID-5667816",
                        "CSAFPID-5737696",
                        "CSAFPID-5737697",
                        "CSAFPID-5737698",
                        "CSAFPID-5875108",
                        "CSAFPID-5892271",
                        "CSAFPID-5902377",
                        "CSAFPID-5902769",
                        "CSAFPID-5907976",
                        "CSAFPID-5907977",
                        "CSAFPID-5907978",
                        "CSAFPID-5907979",
                        "CSAFPID-5907980",
                        "CSAFPID-5907981",
                        "CSAFPID-5912906"
                    ]
                }
            ],
            "title": "CVE-2026-33484"
        }
    ]
}