PT-2026-34737 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41272

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description The core security wrappers secureAxiosRequest() and secureFetch(), designed to prevent Server-Side Request Forgery (SSRF), contain logic flaws. These flaws enable attackers to bypass allow or deny lists through DNS Rebinding, a Time-of-Check Time-of-Use (TOCTOU) race condition where a domain name resolves to a safe IP during validation but a malicious IP during the actual request, or by exploiting a default configuration that does not enforce a deny list.
Recommendations Update to version 3.1.0.

Exploit

Fix

Time Of Check To Time Of Use

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41272
GHSA-2X8M-83VC-6WV4

Affected Products

Flowise