Common Weakness Enumeration

CWE-228

Allowed-with-Review

Improper Handling of Syntactically Invalid Structure

Abstraction: Class · Status: Incomplete

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

40 vulnerabilities reference this CWE, most recent first.

GHSA-3W7P-3W6W-7FPG

Vulnerability from github – Published: 2024-04-22 12:30 – Updated: 2024-07-03 18:36
VLAI
Details

An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted commands.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-22815"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-04-22T12:15:07Z",
    "severity": "MODERATE"
  },
  "details": "An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted commands.",
  "id": "GHSA-3w7p-3w6w-7fpg",
  "modified": "2024-07-03T18:36:23Z",
  "published": "2024-04-22T12:30:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22815"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5WR9-JP8M-F367

Vulnerability from github – Published: 2025-03-11 15:31 – Updated: 2025-03-11 15:31
VLAI
Details

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-42784"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-11T15:15:40Z",
    "severity": "MODERATE"
  },
  "details": "An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.",
  "id": "GHSA-5wr9-jp8m-f367",
  "modified": "2025-03-11T15:31:01Z",
  "published": "2025-03-11T15:31:01Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42784"
    },
    {
      "type": "WEB",
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-115"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6JMW-6MXW-W4JC

Vulnerability from github – Published: 2023-09-13 15:31 – Updated: 2024-09-11 18:45
VLAI
Summary
BER/CER/DER decoder panics on invalid input
Details

NLnet Labs’ bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "crates.io",
        "name": "bcder"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.7.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2023-39914"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228",
      "CWE-232"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-09-14T16:41:57Z",
    "nvd_published_at": "2023-09-13T15:15:07Z",
    "severity": "HIGH"
  },
  "details": "NLnet Labs\u2019 bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.",
  "id": "GHSA-6jmw-6mxw-w4jc",
  "modified": "2024-09-11T18:45:42Z",
  "published": "2023-09-13T15:31:14Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39914"
    },
    {
      "type": "WEB",
      "url": "https://github.com/NLnetLabs/bcder/commit/4da91c3fd853e3d466d8581cf1d82b7f3255de56"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/NLnetLabs/bcder"
    },
    {
      "type": "WEB",
      "url": "https://nlnetlabs.nl/downloads/bcder/CVE-2023-39914.txt"
    },
    {
      "type": "WEB",
      "url": "https://rustsec.org/advisories/RUSTSEC-2023-0062.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "BER/CER/DER decoder panics on invalid input"
}

GHSA-7HXW-QVVV-V969

Vulnerability from github – Published: 2026-06-05 15:32 – Updated: 2026-06-05 15:32
VLAI
Details

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-59174"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-05T15:16:40Z",
    "severity": "HIGH"
  },
  "details": "Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.",
  "id": "GHSA-7hxw-qvvv-v969",
  "modified": "2026-06-05T15:32:25Z",
  "published": "2026-06-05T15:32:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59174"
    },
    {
      "type": "WEB",
      "url": "https://ericsson.com/en/about-us/security/psirt/CVE-2025-59174"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-8M95-FFFC-H4C5

Vulnerability from github – Published: 2025-05-09 06:32 – Updated: 2025-05-09 15:53
VLAI
Summary
libsql-sqlite3-parser crash due to invalid UTF-8 input
Details

dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "crates.io",
        "name": "libsql-sqlite3-parser"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "0.13.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-47736"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-09T15:53:43Z",
    "nvd_published_at": "2025-05-09T05:15:51Z",
    "severity": "LOW"
  },
  "details": "dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.",
  "id": "GHSA-8m95-fffc-h4c5",
  "modified": "2025-05-09T15:53:43Z",
  "published": "2025-05-09T06:32:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47736"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gwenn/lemon-rs/issues/86"
    },
    {
      "type": "WEB",
      "url": "https://github.com/tursodatabase/libsql/issues/2052"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gwenn/lemon-rs/pull/8"
    },
    {
      "type": "WEB",
      "url": "https://crates.io/crates/libsql-sqlite3-parser"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "libsql-sqlite3-parser crash due to invalid UTF-8 input"
}

GHSA-FQ6W-J34V-PHJR

Vulnerability from github – Published: 2022-05-06 00:00 – Updated: 2022-05-14 00:03
VLAI
Details

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-38443"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-05-05T17:15:00Z",
    "severity": "CRITICAL"
  },
  "details": "Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.",
  "id": "GHSA-fq6w-j34v-phjr",
  "modified": "2022-05-14T00:03:34Z",
  "published": "2022-05-06T00:00:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38443"
    },
    {
      "type": "WEB",
      "url": "https://projects.eclipse.org/projects/iot.cyclonedds"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-315-02"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-HRHF-2VCR-GHCH

Vulnerability from github – Published: 2025-10-14 19:57 – Updated: 2025-11-18 18:37
VLAI
Summary
CometBFT's invalid BitArray handling can lead to network halt
Details

Name: ASA-2025-003: Invalid BitArray handling can lead to network halt Criticality: High (Considerable Impact; Possible Likelihood per ACMv1.2) Affected versions: <= v0.38.18, <= v0.37.15, and main development branches Affected users: Validators, Full nodes, Users

Description

A bug was discovered in CometBFT's handling of BitArray's that have a mismatch between the BitArray's expected number of Elems for the specified number of Bits. Additional validation was added to prevent processing BitArray's in this invalid state, as well as guards to prevent panics on BitArray methods if one of these invalid states is processed.

Impact

BitArray's are present in a number of messages received from peers. When handling these messages, insufficient validation was applied to prevent processing messages the aforementioned invalid state. In the worst case, nodes will gossip messages to peers in an invalid state before processing them themselves, leading to a network halt (instead of only the node receiving the malicious message crashing).

Patches

The new CometBFT releases v0.38.19 and v0.37.16 fix this issue.

Unreleased code in the main branch is patched as well.

Workarounds

If a node is able to identify a malicious peer sending these payloads, they can ban the ip address using common tools like iptables.

Timeline

  • October 3, 2025, 11:26am EST: Issue reported to Cosmos Labs via an external team (via their Bug Bounty Program).
  • October 3, 2025, 11:59am EST: Issue triaged by core team and core team completes validation of issue.
  • October 6, 2025, 11:14pm EST: Issue reported to the Cosmos Bug Bounty Program (by original white hat reporter).
  • October 9, 2025, 11:15am EST: Pre-notification delivered.
  • October 10, 2025, 11:37am EST: Core team completes patch for the issue.
  • October 14, 2025, 11:00am EST: Patch made available.

This issue was reported by @whoismxuse to the Cosmos Bug Bounty Program on HackerOne on October 6, 2025. If you believe you have found a bug in the Cosmos Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.

If there are questions about Cosmos security efforts, please reach out to our official communication channel at security@cosmoslabs.io.

A Github Security Advisory for this issue is available in the CometBFT repository. For more information about CometBFT, see https://docs.cometbft.com/.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 0.37.15"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/cometbft/cometbft"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.37.16"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 0.38.18"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/cometbft/cometbft"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.38.0-alpha.1"
            },
            {
              "fixed": "0.38.19"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-14T19:57:30Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "Name: ASA-2025-003: Invalid BitArray handling can lead to network halt\nCriticality: High (Considerable Impact; Possible Likelihood per [ACMv1.2](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md))\nAffected versions: `\u003c= v0.38.18`, `\u003c= v0.37.15`, and `main` development branches\nAffected users: Validators, Full nodes, Users\n\n### Description\n\nA bug was discovered in CometBFT\u0027s handling of `BitArray`\u0027s that have a mismatch between the `BitArray`\u0027s expected number of `Elems` for the specified number of `Bits`. Additional validation was added to prevent processing `BitArray`\u0027s in this invalid state, as well as guards to prevent panics on `BitArray` methods if one of these invalid states is processed.\n\n### Impact\n`BitArray`\u0027s are present in a number of messages received from peers. When handling these messages, insufficient validation was applied to prevent processing messages the aforementioned invalid state. In the worst case, nodes will gossip messages to peers in an invalid state before processing them themselves, leading to a network halt (instead of only the node receiving the malicious message crashing). \n\n### Patches\n\nThe new CometBFT releases [v0.38.19](https://github.com/cometbft/cometbft/releases/tag/v0.38.19) and [v0.37.16](https://github.com/cometbft/cometbft/releases/tag/v0.37.16) fix this issue.\n\nUnreleased code in the main branch is patched as well.\n\n### Workarounds\n\nIf a node is able to identify a malicious peer sending these payloads, they can ban the ip address using common tools like `iptables`.\n\n### Timeline\n\n* October 3, 2025, 11:26am EST: Issue reported to Cosmos Labs via an external team (via their Bug Bounty Program).\n* October 3, 2025, 11:59am EST: Issue triaged by core team and core team completes validation of issue.\n* October 6, 2025, 11:14pm EST: Issue reported to the Cosmos Bug Bounty Program (by original white hat reporter).\n* October 9, 2025, 11:15am EST: Pre-notification delivered.\n* October 10, 2025, 11:37am EST: Core team completes patch for the issue.\n* October 14, 2025, 11:00am EST: Patch made available.\n\nThis issue was reported by @whoismxuse to the Cosmos Bug Bounty Program on HackerOne on October 6, 2025. If you believe you have found a bug in the Cosmos Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\nIf there are questions about Cosmos security efforts, please reach out to our official communication channel at [security@cosmoslabs.io](mailto:security@cosmoslabs.io).\n\nA Github Security Advisory for this issue is available in the CometBFT [repository](https://github.com/cometbft/cometbft/security/advisories/GHSA-hrhf-2vcr-ghch). For more information about CometBFT, see https://docs.cometbft.com/.",
  "id": "GHSA-hrhf-2vcr-ghch",
  "modified": "2025-11-18T18:37:25Z",
  "published": "2025-10-14T19:57:30Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/cometbft/cometbft/security/advisories/GHSA-hrhf-2vcr-ghch"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cometbft/cometbft/commit/be5677c3e58f998b7f67bb6186dd2c9b81a041a1"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cometbft/cometbft/commit/dcb1f265b59477be40804f7ccdc4fb30612d6a4f"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/cometbft/cometbft"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cometbft/cometbft/releases/tag/v0.37.16"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cometbft/cometbft/releases/tag/v0.38.19"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "CometBFT\u0027s invalid BitArray handling can lead to network halt"
}

GHSA-JVW3-JCJ6-6QC7

Vulnerability from github – Published: 2026-06-05 12:31 – Updated: 2026-06-08 15:32
VLAI
Details

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-25657"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-05T12:16:37Z",
    "severity": "HIGH"
  },
  "details": "Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.",
  "id": "GHSA-jvw3-jcj6-6qc7",
  "modified": "2026-06-08T15:32:49Z",
  "published": "2026-06-05T12:31:46Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25657"
    },
    {
      "type": "WEB",
      "url": "https://www.ericsson.com/en/about-us/security/psirt/cve-2026-25657"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-JXW3-MJMX-3PQM

Vulnerability from github – Published: 2026-10-05 22:31 – Updated: 2026-10-05 22:31
VLAI
Summary
Langflow: Weak Fernet Key via random.seed()
Details

Summary

Langflow uses Python's random module (Mersenne Twister, a non-cryptographic PRNG) seeded with the SECRET_KEY to derive the Fernet encryption key for all stored user credentials (API keys, LLM provider secrets, database passwords). When the SECRET_KEY is shorter than 32 characters — a common scenario for self-hosted deployments using simple/memorable secrets — the derived encryption key is fully deterministic and reproducible by anyone who knows the seed value. An attacker who obtains the SECRET_KEY (e.g., via the MCP path traversal in this repo) can reconstruct the exact Fernet key offline and decrypt every credential stored in the database with no brute force required.

Even when SECRET_KEY is 32+ characters (the "safe" branch), the raw key material is used directly as the Fernet key — meaning exfiltrating the secret_key file is sufficient to decrypt all credentials without any additional computation.

Severity: Critical — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1) CWE-338: Weak PRNG | CWE-321: Hard-coded Cryptographic Key | CWE-311: Missing Encryption of Sensitive Data

Details

Root cause: src/backend/base/langflow/services/auth/service.py, lines 651–663

MINIMUM_KEY_LENGTH = 32

def _ensure_valid_key(self, raw_key: str) -> bytes:
    if len(raw_key) < MINIMUM_KEY_LENGTH:
        random.seed(raw_key)                                   # Non-cryptographic PRNG seeded with the secret
        key = bytes(random.getrandbits(8) for _ in range(32)) # Fully deterministic output
        key = base64.urlsafe_b64encode(key)
    else:
        key = self._add_padding(raw_key).encode()              # Raw secret IS the Fernet key
    return key

def _get_fernet(self) -> Fernet:
    secret_key = self.settings.auth_settings.SECRET_KEY.get_secret_value()
    valid_key = self._ensure_valid_key(secret_key)
    return Fernet(valid_key)

The identical logic is duplicated in src/backend/base/langflow/services/auth/utils.py, lines 292–318 (called by DatabaseVariableService.create_variable and update_variable).

What is encrypted under this key: All variables stored with type = "Credential" — this is the default for OpenAI API keys, Anthropic API keys, and any secret stored via the Variables UI or API:

# services/variable/service.py
encrypted_value = auth_utils.encrypt_api_key(value) if type_ == CREDENTIAL_TYPE else value

Why this is critical in combination with the MCP path traversal: The secret_key file is stored at /app/data/.cache/langflow/secret_key — readable via the MCP path traversal vulnerability. Once exfiltrated: - If len(secret_key) < 32: run random.seed(secret_key) → derive identical key → decrypt all credentials instantly - If len(secret_key) >= 32: pad the key directly → decrypt all credentials instantly

No brute force needed in either case once the file is read.

PoC

#!/usr/bin/env python3
# Requires: pip install cryptography

import random
import base64
from cryptography.fernet import Fernet

# --- Scenario A: SHORT secret key (< 32 chars) --- triggers vulnerable PRNG branch
def decrypt_short_key(secret_key: str, ciphertext: str) -> str:
    random.seed(secret_key)
    key_bytes = bytes(random.getrandbits(8) for _ in range(32))
    fernet_key = base64.urlsafe_b64encode(key_bytes)
    return Fernet(fernet_key).decrypt(ciphertext.encode()).decode()

# --- Scenario B: LONG secret key (>= 32 chars) --- key exfiltration scenario
def decrypt_long_key(secret_key: str, ciphertext: str) -> str:
    padding_needed = 4 - len(secret_key) % 4
    padded = secret_key + "=" * padding_needed
    return Fernet(padded.encode()).decrypt(ciphertext.encode()).decode()

# Values obtained from /app/data/.cache/langflow/secret_key (exfiltrated)
# and from SELECT value FROM variable WHERE type='Credential' in langflow.db
SECRET_KEY = "DJMcAXyLbLrKRmPRTBNlJzY4gkbe3g1lyDgJ90c8p0E"  # 43 chars → long branch
CIPHERTEXT = "gAAAAABpux-Gz_3PFcaPJF1aqZAUfB76OomPJ8rvp9Q8hKvBVG_GgvSIdWwgknXqO0rVUbfSiflKFp6wDdeU9uWy_sPsKPLBr_i5ZOPAAP2c5EKkx5vtc1M="

plaintext = decrypt_long_key(SECRET_KEY, CIPHERTEXT)
print(f"Decrypted credential: {plaintext}")
# Output: sk-test-SENTINEL-VALUE-12345

Confirmed on Langflow v1.7.3: - Database path: /app/.venv/lib/python3.12/site-packages/langflow/langflow.db - Two Credential-type variables found in the variable table - Both decrypted successfully: "dummy" and "sk-test-SENTINEL-VALUE-12345" - The sentinel value (sk-test-SENTINEL-VALUE-12345) was stored via the API and immediately recovered from raw DB ciphertext using only the exfiltrated secret_key

End-to-end chain (with MCP path traversal):

# Step 1: Exfiltrate secret_key via MCP path traversal (no admin required, any authenticated user)
# Step 2: Query DB credentials via path traversal (SQLite file readable)
# Step 3: Decrypt offline — zero brute force, instant
python3 poc_decrypt.py "$SECRET_KEY" "$CIPHERTEXT"
# → all stored API keys revealed

Impact

All stored user credentials are at risk in any Langflow deployment where an attacker can read the secret_key file. Combined with the MCP path traversal vulnerability, this creates a complete remote credential exfiltration chain requiring only a low-privilege account:

  • OpenAI, Anthropic, and other LLM provider API keys stored by any user are decryptable
  • Database connection strings and passwords stored as credentials are exposed
  • OAuth tokens and webhook secrets stored via the Variables UI are exposed
  • All users on the instance are affected — credentials are stored per-user in the shared database but all encrypted under the same instance-wide SECRET_KEY

In multi-tenant or enterprise Langflow deployments, a single attacker account is sufficient to exfiltrate every credential stored by every user on the instance. The attack is fully offline after the two file reads (secret_key + database), leaving no server-side log traces.

Fix

Fixed in v1.10.1 by PR #13704 (commit 094694d3f2).

ensure_fernet_key() (src/backend/base/langflow/services/auth/utils.py) no longer seeds Python's non-cryptographic random module for short SECRET_KEY values. The 32-byte key is now derived deterministically with SHA-256:

def ensure_fernet_key(secret_key: str) -> bytes:
    if len(secret_key) < MINIMUM_SECRET_KEY_LENGTH:
        digest = hashlib.sha256(secret_key.encode()).digest()  # 32 bytes
        key = base64.urlsafe_b64encode(digest)
    else:
        key = add_base64_padding(secret_key).encode()
    return key

Backward-compatible decryption of ciphertext written under the old PRNG-derived key is preserved via get_fernet_for_decryption(), which returns a MultiFernet trying the new SHA-256 key first and a legacy key second. The legacy key is reproduced with a local random.Random(secret_key) instance (not the global random module), so it can decrypt old data without ever being usable to derive new keys or mutating global PRNG state. All new encryption goes through the SHA-256 key only.

Affected versions: <= 1.10.0 Patched version: 1.10.1

Operator note: deployments running with a SECRET_KEY shorter than 32 characters derive a different Fernet key after upgrading to 1.10.1+ and must re-enter previously stored credentials (existing ciphertext is still readable for migration, but new writes use the new key). The default generated SECRET_KEY (secrets.token_urlsafe(32), 43 characters) takes the long-key branch and was never affected by the PRNG issue.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 1.10.0"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "langflow"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.10.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-9205"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T22:31:35Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
  },
  "details": "### Summary\n\nLangflow uses Python\u0027s `random` module (Mersenne Twister, a non-cryptographic PRNG) seeded with the `SECRET_KEY` to derive the Fernet encryption key for all stored user credentials (API keys, LLM provider secrets, database passwords). When the `SECRET_KEY` is shorter than 32 characters \u2014 a common scenario for self-hosted deployments using simple/memorable secrets \u2014 the derived encryption key is fully deterministic and reproducible by anyone who knows the seed value. An attacker who obtains the `SECRET_KEY` (e.g., via the MCP path traversal in this repo) can reconstruct the exact Fernet key offline and decrypt every credential stored in the database with no brute force required.\n\nEven when `SECRET_KEY` is 32+ characters (the \"safe\" branch), the raw key material is used directly as the Fernet key \u2014 meaning exfiltrating the `secret_key` file is sufficient to decrypt all credentials without any additional computation.\n\n**Severity:** Critical \u2014 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1)\n**CWE-338:** Weak PRNG | **CWE-321:** Hard-coded Cryptographic Key | **CWE-311:** Missing Encryption of Sensitive Data\n\n### Details\n\n**Root cause: `src/backend/base/langflow/services/auth/service.py`, lines 651\u2013663**\n\n```python\nMINIMUM_KEY_LENGTH = 32\n\ndef _ensure_valid_key(self, raw_key: str) -\u003e bytes:\n    if len(raw_key) \u003c MINIMUM_KEY_LENGTH:\n        random.seed(raw_key)                                   # Non-cryptographic PRNG seeded with the secret\n        key = bytes(random.getrandbits(8) for _ in range(32)) # Fully deterministic output\n        key = base64.urlsafe_b64encode(key)\n    else:\n        key = self._add_padding(raw_key).encode()              # Raw secret IS the Fernet key\n    return key\n\ndef _get_fernet(self) -\u003e Fernet:\n    secret_key = self.settings.auth_settings.SECRET_KEY.get_secret_value()\n    valid_key = self._ensure_valid_key(secret_key)\n    return Fernet(valid_key)\n```\n\nThe identical logic is duplicated in `src/backend/base/langflow/services/auth/utils.py`, lines 292\u2013318 (called by `DatabaseVariableService.create_variable` and `update_variable`).\n\n**What is encrypted under this key:**\nAll variables stored with `type = \"Credential\"` \u2014 this is the default for OpenAI API keys, Anthropic API keys, and any secret stored via the Variables UI or API:\n\n```python\n# services/variable/service.py\nencrypted_value = auth_utils.encrypt_api_key(value) if type_ == CREDENTIAL_TYPE else value\n```\n\n**Why this is critical in combination with the [MCP path traversal](https://github.com/langflow-ai/langflow/security/advisories/GHSA-95rw-c7w3-xh7f):**\nThe `secret_key` file is stored at `/app/data/.cache/langflow/secret_key` \u2014 readable via the MCP path traversal vulnerability. Once exfiltrated:\n- If `len(secret_key) \u003c 32`: run `random.seed(secret_key)` \u2192 derive identical key \u2192 decrypt all credentials instantly\n- If `len(secret_key) \u003e= 32`: pad the key directly \u2192 decrypt all credentials instantly\n\nNo brute force needed in either case once the file is read.\n\n### PoC\n\n```python\n#!/usr/bin/env python3\n# Requires: pip install cryptography\n\nimport random\nimport base64\nfrom cryptography.fernet import Fernet\n\n# --- Scenario A: SHORT secret key (\u003c 32 chars) --- triggers vulnerable PRNG branch\ndef decrypt_short_key(secret_key: str, ciphertext: str) -\u003e str:\n    random.seed(secret_key)\n    key_bytes = bytes(random.getrandbits(8) for _ in range(32))\n    fernet_key = base64.urlsafe_b64encode(key_bytes)\n    return Fernet(fernet_key).decrypt(ciphertext.encode()).decode()\n\n# --- Scenario B: LONG secret key (\u003e= 32 chars) --- key exfiltration scenario\ndef decrypt_long_key(secret_key: str, ciphertext: str) -\u003e str:\n    padding_needed = 4 - len(secret_key) % 4\n    padded = secret_key + \"=\" * padding_needed\n    return Fernet(padded.encode()).decrypt(ciphertext.encode()).decode()\n\n# Values obtained from /app/data/.cache/langflow/secret_key (exfiltrated)\n# and from SELECT value FROM variable WHERE type=\u0027Credential\u0027 in langflow.db\nSECRET_KEY = \"DJMcAXyLbLrKRmPRTBNlJzY4gkbe3g1lyDgJ90c8p0E\"  # 43 chars \u2192 long branch\nCIPHERTEXT = \"gAAAAABpux-Gz_3PFcaPJF1aqZAUfB76OomPJ8rvp9Q8hKvBVG_GgvSIdWwgknXqO0rVUbfSiflKFp6wDdeU9uWy_sPsKPLBr_i5ZOPAAP2c5EKkx5vtc1M=\"\n\nplaintext = decrypt_long_key(SECRET_KEY, CIPHERTEXT)\nprint(f\"Decrypted credential: {plaintext}\")\n# Output: sk-test-SENTINEL-VALUE-12345\n```\n\n**Confirmed on Langflow v1.7.3:**\n- Database path: `/app/.venv/lib/python3.12/site-packages/langflow/langflow.db`\n- Two `Credential`-type variables found in the `variable` table\n- Both decrypted successfully: `\"dummy\"` and `\"sk-test-SENTINEL-VALUE-12345\"`\n- The sentinel value (`sk-test-SENTINEL-VALUE-12345`) was stored via the API and immediately recovered from raw DB ciphertext using only the exfiltrated `secret_key`\n\n**End-to-end chain (with MCP path traversal):**\n```bash\n# Step 1: Exfiltrate secret_key via MCP path traversal (no admin required, any authenticated user)\n# Step 2: Query DB credentials via path traversal (SQLite file readable)\n# Step 3: Decrypt offline \u2014 zero brute force, instant\npython3 poc_decrypt.py \"$SECRET_KEY\" \"$CIPHERTEXT\"\n# \u2192 all stored API keys revealed\n```\n\n### Impact\n\nAll stored user credentials are at risk in any Langflow deployment where an attacker can read the `secret_key` file. Combined with the MCP path traversal vulnerability, this creates a complete remote credential exfiltration chain requiring only a low-privilege account:\n\n- **OpenAI, Anthropic, and other LLM provider API keys** stored by any user are decryptable\n- **Database connection strings and passwords** stored as credentials are exposed\n- **OAuth tokens and webhook secrets** stored via the Variables UI are exposed\n- **All users on the instance** are affected \u2014 credentials are stored per-user in the shared database but all encrypted under the same instance-wide `SECRET_KEY`\n\nIn multi-tenant or enterprise Langflow deployments, a single attacker account is sufficient to exfiltrate every credential stored by every user on the instance. The attack is fully offline after the two file reads (secret_key + database), leaving no server-side log traces.\n\n\n### Fix\n\nFixed in **v1.10.1** by PR [#13704](https://github.com/langflow-ai/langflow/pull/13704) (commit `094694d3f2`).\n\n`ensure_fernet_key()` (`src/backend/base/langflow/services/auth/utils.py`) no longer seeds Python\u0027s non-cryptographic `random` module for short `SECRET_KEY` values. The 32-byte key is now derived deterministically with SHA-256:\n\n```python\ndef ensure_fernet_key(secret_key: str) -\u003e bytes:\n    if len(secret_key) \u003c MINIMUM_SECRET_KEY_LENGTH:\n        digest = hashlib.sha256(secret_key.encode()).digest()  # 32 bytes\n        key = base64.urlsafe_b64encode(digest)\n    else:\n        key = add_base64_padding(secret_key).encode()\n    return key\n```\n\nBackward-compatible decryption of ciphertext written under the old PRNG-derived key is preserved via `get_fernet_for_decryption()`, which returns a `MultiFernet` trying the new SHA-256 key first and a legacy key second. The legacy key is reproduced with a local `random.Random(secret_key)` instance (not the global `random` module), so it can decrypt old data without ever being usable to derive new keys or mutating global PRNG state. All new encryption goes through the SHA-256 key only.\n\n**Affected versions:** \u003c= 1.10.0\n**Patched version:** 1.10.1\n\n**Operator note:** deployments running with a `SECRET_KEY` shorter than 32 characters derive a different Fernet key after upgrading to 1.10.1+ and must re-enter previously stored credentials (existing ciphertext is still readable for migration, but new writes use the new key). The default generated `SECRET_KEY` (`secrets.token_urlsafe(32)`, 43 characters) takes the long-key branch and was never affected by the PRNG issue.",
  "id": "GHSA-jxw3-mjmx-3pqm",
  "modified": "2026-10-05T22:31:36Z",
  "published": "2026-10-05T22:31:35Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-jxw3-mjmx-3pqm"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9205"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langflow-ai/langflow/pull/13704"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langflow-ai/langflow/commit/094694d3f20c1da499f4d8dbac15c510609e3026"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/langflow-ai/langflow"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7282648"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Langflow: Weak Fernet Key via random.seed()"
}

GHSA-M755-674G-G2X5

Vulnerability from github – Published: 2024-04-22 12:30 – Updated: 2024-07-03 18:36
VLAI
Details

Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-22809"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-228"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-04-22T12:15:07Z",
    "severity": "MODERATE"
  },
  "details": "Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code\u0027s shared folder and view sensitive information.",
  "id": "GHSA-m755-674g-g2x5",
  "modified": "2024-07-03T18:36:21Z",
  "published": "2024-04-22T12:30:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22809"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.