CVE-2026-10564: SSRF in IBM Langflow OSS RSS and SearXNG components
IBM Langflow OSS versions 1.0.0 through 1.9.6 contain a server-side request forgery flaw in the legacy RSSReaderComponent and SearXNG component, which make unvalidated HTTP requests to user-controlled URLs and bypass SSRF protections added in 1.9.3. An authenticated attacker, or an attacker using prompt injection against agentic workflows where the components are exposed as tools, can reach internal resources such as cloud metadata services and potentially exfiltrate IAM credentials.
Disclosed 30 June 2026 · Record updated 13 September 2026
Impact
Allows access to internal resources including AWS/Azure/GCP instance metadata services, potentially exfiltrating IAM credentials and enumerating internal networks.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-10564
