Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2026-9081

CVSS Base Score
7.1 HIGH
Primary Weakness
CWE-918
Published Date
Aug 5, 2026
Data Source
NVD API

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, link-local addresses).

Related Vulnerabilitiesvia CWE-918

CVE-2026-3543110 CRITICAL

Server-Side Request Forgery (SSRF) in Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network

CWE-918
CVE-2026-322109.3 CRITICAL

Server-Side Request Forgery (SSRF) in Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network

CWE-918
CVE-2026-3218610 CRITICAL

Server-Side Request Forgery (SSRF) in Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network

CWE-918
CVE-2026-48740 LOW

CVE-2026-4874: Server-Side Request Forgery in Keycloak

CWE-918
CVE-2026-45287.3 HIGH

A vulnerability was determined in trueleaf ApiFlow 0.

CWE-918
CVE-2024-562796.5 MEDIUM

Server-Side Request Forgery (SSRF) — Cloud metadata access

CWE-918

Is your system affected?

Precogs AI detects CVE-2026-9081 in compiled binaries, LLMs, and application layers — even without source code access.