CVE-2026-55446: Langflow: Unauthenticated DoS through multipart form boundary file upload
An attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55446 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →