Langflow known exploited vulnerabilities
CISA lists 5 Langflow CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-07-21), and 1 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2025-3248 (Langflow): EPSS 100.0%, added 2025-05-05
- CVE-2025-34291 (Langflow): EPSS 92.8%, added 2026-05-21
- CVE-2026-0770 (Langflow): EPSS 63.8%, added 2026-07-21
- CVE-2026-33017 (Langflow): EPSS 24.8%, added 2026-03-25
- CVE-2026-55255 (Langflow): EPSS 0.9%, added 2026-07-07
Most affected Langflow products
Langflow (5).
All Langflow CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-0770 | Langflow | Inclusion of Functionality from Untrusted Control Sphere | 2026-07-21 | 2026-07-24 | 63.8% | – |
| CVE-2026-55255 | Langflow | Authorization Bypass Through User-Controlled Key | 2026-07-07 | 2026-07-10 | 0.9% | – |
| CVE-2025-34291 | Langflow | Origin Validation Error | 2026-05-21 | 2026-06-04 | 92.8% | – |
| CVE-2026-33017 | Langflow | Code Injection | 2026-03-25 | 2026-04-08 | 24.8% | – |
| CVE-2025-3248 | Langflow | Missing Authentication | 2025-05-05 | 2025-05-26 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors