CVE-2026-5027: Langflow <= 1.8.4 - Path Traversal to RCE via File Upload

HoneyLabs honeypots recorded 5 probes matching CVE-2026-5027 from 2 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /api/v2/files
  • /api/v1/auto_login

Addresses probing it

Source IPProbesNetworkCountry
176.65.148.2264Pfcloud UG (haftungsbeschrankt)The Netherlands
174.172.60.1271Comcast Cable Communications, LLCUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS51396Pfcloud UG (haftungsbeschrankt)41
AS7922Comcast Cable Communications, LLC11

Captured requests

  • /api/v1/auto_login

HTTP client fingerprints (JA4H)

  • ge11nn0200_f24fcf356134
  • ge11nn0500_cac2c496544b

CVE report

CVE report

Open a specific CVE from the CVE tracker.