Langflow security patch release for CVE-2026-5027
Security Patch Release
Summary
Hide ▲
Show ▼
Langflow shipped fixes for CVE-2026-5027, closing a path traversal flaw that let attackers write arbitrary files on exposed servers. The patch landed in langflow-base 0.8.3 and Langflow 1.9.0. The release matters because the vulnerable upload path was already being used in active exploitation.
Related Happenings
FFmpeg 8.1.2 security update (CVE-2026-8461)
Security Patch Release
H score36
First: 23.06.2026 00:05
Last: 23.06.2026 00:05
Sources 1
About this happening:
FFmpeg shipped version 8.1.2 to fix CVE-2026-8461 in the MagicYUV decoder, closing a heap out-of-bounds write that could affect FFmpeg-based applications. The...
FFmpeg 8.1.2 security update (CVE-2026-8461)
Security Patch ReleaseAbout this happening: FFmpeg shipped version 8.1.2 to fix CVE-2026-8461 in the MagicYUV decoder, closing a heap out-of-bounds write that could affect FFmpeg-based applications. The...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
CPanel security patch release for CVE-2026-29201
Security Patch Release
H score34
First: 09.05.2026 10:16
Last: 09.05.2026 10:16
Sources 1
About this happening:
cPanel released updates for cPanel and Web Host Manager (WHM) to fix three vulnerabilities that could enable privilege escalation, code execution, or denial-...
CPanel security patch release for CVE-2026-29201
Security Patch ReleaseAbout this happening: cPanel released updates for cPanel and Web Host Manager (WHM) to fix three vulnerabilities that could enable privilege escalation, code execution, or denial-...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch Release
H score39
First: 30.04.2026 16:54
Last: 30.04.2026 16:54
Sources 1
About this happening:
Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch ReleaseAbout this happening: Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Timeline
-
30.03.2026 03:00 2 articles · 3mo ago
Langflow and langflow-base ship fixes for CVE-2026-5027
Mitigation Patch UpdateLangflow and the langflow-base package received fixes for CVE-2026-5027, a path traversal flaw in the POST /api/v2/files upload path that allowed arbitrary file writes through unsanitized filename values. The affected releases were langflow-base 0.8.3 and Langflow 1.9.0.
Show sources
- Path traversal flaw in AI dev platform Langflow exploited in attacks — www.bleepingcomputer.com — 11.06.2026 00:23
- Path traversal flaw in AI dev platform Langflow exploited in attacks — www.bleepingcomputer.com — 11.06.2026 00:23