{"success":true,"data":{"threats":[{"id":"c3fe01a2-53f3-44ed-9c8b-a799bd5055e2","slug":"cve-2026-46570","externalId":"CVE-2026-46570","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46570 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap m…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.","cveId":"CVE-2026-46570","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-m6qq-pv5j-2wxc"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-m6qq-pv5j-2wxc","type":"patch","title":"Patch"}],"epssScore":0.00128,"epssPercentile":0.02135,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:21.010Z","addedAt":"2026-10-07T16:39:32.516Z","updatedAt":"2026-10-08T19:33:16.617Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46570","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46570","note":"authoritative record"}]},{"id":"306f6b6a-8883-475c-9fe9-17c79af42c6f","slug":"cve-2026-46572","externalId":"CVE-2026-46572","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46572 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memor…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.","cveId":"CVE-2026-46572","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-wx5r-gc7w-9hhc"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-wx5r-gc7w-9hhc","type":"patch","title":"Patch"}],"epssScore":0.00128,"epssPercentile":0.02135,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:11.470Z","addedAt":"2026-10-07T14:39:35.296Z","updatedAt":"2026-10-08T19:33:16.600Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46572","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46572","note":"authoritative record"}]},{"id":"91dcb161-c393-47ca-9dea-5b0d2d81d7e9","slug":"cve-2026-46571","externalId":"CVE-2026-46571","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46571 — In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly co…","description":"In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file.","cveId":"CVE-2026-46571","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-125"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-52gr-j4pv-9pjh"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-52gr-j4pv-9pjh","type":"patch","title":"Mitigation"}],"epssScore":0.00114,"epssPercentile":0.01356,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:10.980Z","addedAt":"2026-10-07T14:39:35.288Z","updatedAt":"2026-10-08T19:33:16.580Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46571","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46571","note":"authoritative record"}]},{"id":"a1a6348a-9191-49cd-92cf-56450e7d8733","slug":"cve-2026-46569","externalId":"CVE-2026-46569","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46569 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap me…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.","cveId":"CVE-2026-46569","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xxv8-9r24-hcj9"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xxv8-9r24-hcj9","type":"patch","title":"Patch"}],"epssScore":0.00169,"epssPercentile":0.05666,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:10.833Z","addedAt":"2026-10-07T14:39:35.280Z","updatedAt":"2026-10-08T19:33:16.560Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46569","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46569","note":"authoritative record"}]},{"id":"13666092-2b6e-4831-8f17-e6ba4f9e61ab","slug":"cve-2026-42618","externalId":"CVE-2026-42618","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42618 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap me…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.","cveId":"CVE-2026-42618","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122","CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw","type":"patch","title":"Patch"}],"epssScore":0.00126,"epssPercentile":0.02033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.740Z","addedAt":"2026-10-07T14:39:35.233Z","updatedAt":"2026-10-08T19:33:16.540Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42618","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42618","note":"authoritative record"}]},{"id":"1c8bfd16-8fa0-49d7-800a-959788f24088","slug":"cve-2026-42617","externalId":"CVE-2026-42617","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42617 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.","cveId":"CVE-2026-42617","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-jv65-qqf7-f692"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-jv65-qqf7-f692","type":"patch","title":"Patch"}],"epssScore":0.00126,"epssPercentile":0.02033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.587Z","addedAt":"2026-10-07T14:39:35.226Z","updatedAt":"2026-10-08T19:33:16.520Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42617","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42617","note":"authoritative record"}]},{"id":"e76a391b-1808-430d-ab17-9a2636a6b00c","slug":"cve-2026-42616","externalId":"CVE-2026-42616","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42616 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binar…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.","cveId":"CVE-2026-42616","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-p6mp-gp2j-7358"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-p6mp-gp2j-7358","type":"patch","title":"Patch"}],"epssScore":0.00169,"epssPercentile":0.05666,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.423Z","addedAt":"2026-10-07T14:39:35.220Z","updatedAt":"2026-10-08T19:33:16.498Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42616","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42616","note":"authoritative record"}]},{"id":"0e338e5c-3a65-4fe3-81ae-e6545856c14b","slug":"cve-2026-97680","externalId":"CVE-2026-97680","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97680 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to i…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.","cveId":"CVE-2026-97680","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-284"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00266,"epssPercentile":0.17001,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.780Z","addedAt":"2026-10-07T02:39:29.158Z","updatedAt":"2026-10-08T04:39:32.713Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97680","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97680","note":"authoritative record"}]},{"id":"b5b3eb49-3931-4764-af28-6c7484496727","slug":"cve-2026-97679","externalId":"CVE-2026-97679","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97679 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of speci…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.","cveId":"CVE-2026-97679","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-94"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00449,"epssPercentile":0.36979,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.643Z","addedAt":"2026-10-07T02:39:29.151Z","updatedAt":"2026-10-08T04:39:32.701Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97679","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97679","note":"authoritative record"}]},{"id":"80bc0017-6d68-4c04-9a4e-123b35e1368e","slug":"cve-2026-97678","externalId":"CVE-2026-97678","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97678 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.","cveId":"CVE-2026-97678","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-693"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00415,"epssPercentile":0.33747,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.517Z","addedAt":"2026-10-07T02:39:29.143Z","updatedAt":"2026-10-08T14:40:02.059Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97678","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97678","note":"authoritative record"}]},{"id":"6af4e460-de38-4a31-9ca8-28b3de6bba9b","slug":"cve-2026-97676","externalId":"CVE-2026-97676","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97676 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of speci…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.","cveId":"CVE-2026-97676","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-94"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00548,"epssPercentile":0.44128,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.387Z","addedAt":"2026-10-07T02:39:29.135Z","updatedAt":"2026-10-08T04:39:32.676Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97676","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97676","note":"authoritative record"}]},{"id":"01d2bf8c-e76b-46d9-b346-a4b9e9ff6878","slug":"cve-2026-97674","externalId":"CVE-2026-97674","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97674 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization o…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.","cveId":"CVE-2026-97674","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-94"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.003,"epssPercentile":0.20874,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.247Z","addedAt":"2026-10-07T02:39:29.128Z","updatedAt":"2026-10-08T14:40:02.044Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97674","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97674","note":"authoritative record"}]},{"id":"e62f56de-84fa-4486-a37d-cb73bee669f6","slug":"cve-2026-97673","externalId":"CVE-2026-97673","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97673 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.","cveId":"CVE-2026-97673","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-693"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00445,"epssPercentile":0.36719,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:36.117Z","addedAt":"2026-10-07T02:39:29.120Z","updatedAt":"2026-10-08T04:39:32.651Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97673","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97673","note":"authoritative record"}]},{"id":"dafa55d0-2977-4154-911c-bedf47b6e198","slug":"cve-2026-97671","externalId":"CVE-2026-97671","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97671 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerabi…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.","cveId":"CVE-2026-97671","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-22"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00456,"epssPercentile":0.37608,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.980Z","addedAt":"2026-10-07T02:39:29.113Z","updatedAt":"2026-10-08T02:39:29.821Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97671","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97671","note":"authoritative record"}]},{"id":"d292b544-e73d-4639-a3b7-02111e8641d4","slug":"cve-2026-97655","externalId":"CVE-2026-97655","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97655 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security s…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.","cveId":"CVE-2026-97655","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-94"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00548,"epssPercentile":0.44127,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.833Z","addedAt":"2026-10-07T02:39:29.105Z","updatedAt":"2026-10-08T14:40:02.029Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97655","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97655","note":"authoritative record"}]},{"id":"c0ad4eb9-6bd5-46e1-8a1e-3fc963ecf00a","slug":"cve-2026-93679","externalId":"CVE-2026-93679","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93679 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consump…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.","cveId":"CVE-2026-93679","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-400"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0048,"epssPercentile":0.39442,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.710Z","addedAt":"2026-10-07T02:39:29.098Z","updatedAt":"2026-10-08T02:39:29.800Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93679","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93679","note":"authoritative record"}]},{"id":"23403325-f18f-42e7-8da0-a58027eb6e0c","slug":"cve-2026-93678","externalId":"CVE-2026-93678","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93678 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.","cveId":"CVE-2026-93678","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","severity":"high","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-639"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00382,"epssPercentile":0.30088,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.580Z","addedAt":"2026-10-07T02:39:29.090Z","updatedAt":"2026-10-08T02:39:29.790Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93678","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93678","note":"authoritative record"}]},{"id":"1046f7ea-3060-477f-a999-aff809681878","slug":"cve-2026-93677","externalId":"CVE-2026-93677","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93677 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive info…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.","cveId":"CVE-2026-93677","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-200"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0046,"epssPercentile":0.37839,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.457Z","addedAt":"2026-10-07T02:39:29.083Z","updatedAt":"2026-10-08T18:39:30.520Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93677","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93677","note":"authoritative record"}]},{"id":"045cfaa5-247a-4d2f-bee0-ef9156f1164b","slug":"cve-2026-93675","externalId":"CVE-2026-93675","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93675 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.","cveId":"CVE-2026-93675","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-440"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00678,"epssPercentile":0.50823,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.320Z","addedAt":"2026-10-07T02:39:29.075Z","updatedAt":"2026-10-08T18:39:30.509Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93675","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93675","note":"authoritative record"}]},{"id":"8863c2f2-f615-41e8-9283-cb1b2d35dd16","slug":"cve-2026-93674","externalId":"CVE-2026-93674","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93674 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements us…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.","cveId":"CVE-2026-93674","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-94"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00756,"epssPercentile":0.53767,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:35.187Z","addedAt":"2026-10-07T02:39:29.066Z","updatedAt":"2026-10-08T18:39:30.499Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93674","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93674","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":19923,"totalPages":997,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:57:39.011Z","durationMs":153,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["status:analyzed"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}