CVE report
CVE-2026-5027high
Langflow <= 1.8.4 - Path Traversal to RCE via File Upload
Events 90d
479
Distinct IPs
40
Severity
high
CISA KEV
Not listed
Detection signature
An event counts toward CVE-2026-5027 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /api/v1/login
- · /api/v2/files
- · /api/v1/auto_login
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 154 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2026-5027
- 172.245.21.3090 eventsUnited States· HostPapa
- 34.145.99.7328 eventsUnited States
- 185.242.3.518 eventsNetherlands· Netiface Limited
- 34.131.191.15914 eventsIndia
- 34.32.98.23214 eventsGermany
- 34.21.154.21214 eventsSingapore
- 34.100.199.114 eventsIndia
- 34.162.180.10714 eventsUnited States
- 34.14.215.5714 eventsIndia
- 35.240.178.5614 eventsSingapore
- 34.21.208.19114 eventsSingapore
- 34.93.154.7714 eventsIndia
- 34.65.98.11514 eventsSwitzerland
- 34.40.152.10314 eventsAustralia
- 34.17.165.514 eventsItaly
- 34.131.119.25114 eventsIndia
- 194.110.87.21614 eventsBulgaria· DA International Group Ltd.
- 34.172.164.11914 eventsUnited States
- 34.21.152.21714 eventsSingapore
- 34.18.217.2114 eventsQatar
- 34.93.24.8414 eventsIndia
- 35.234.81.6614 eventsGermany
- 34.158.194.22514 eventsSouth Korea
- 34.6.123.14014 eventsNetherlands
- 34.130.62.23114 eventsCanada
- 185.242.3.8210 eventsThe Netherlands· Netiface America, Inc.
- 54.161.68.686 eventsUnited States
- 45.225.135.184 eventsPanama· RACK SPHERE HOSTING S.A.
- 146.70.119.222 eventsUnited Kingdom· M247 Europe SRL
- 87.121.84.1672 eventsUnited States· TechTies Inc.
Top networks the attempts come from
- AS396982 Google LLC22 IPs · 322 ev
- AS36352 HostPapa1 IPs · 90 ev
- AS401626 Netiface America, Inc.3 IPs · 23 ev
- AS203380 DA International Group Ltd.1 IPs · 14 ev
- AS14618 Amazon.com, Inc.1 IPs · 6 ev
- AS60223 Netiface Limited1 IPs · 6 ev
- AS64107 RACK SPHERE HOSTING S.A.1 IPs · 4 ev
- AS9009 M247 Europe SRL2 IPs · 3 ev
- AS197706 Keminet SHPK1 IPs · 2 ev
- AS39351 31173 Services AB2 IPs · 2 ev
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
ja4h: ge11nn0400_88d30a62b7adja4h: po11nn16en_95ea7cb0e7eeja4h: ge11nn0300_0db47b7d240dja4h: po11nn0500_b4ba55311b46ja4h: ge11nn0400_17292dadbc7bja4h: ge11nn0500_e161b8ad0830ja4: t13i1515h2_8daaf6152771_e5627efa2ab1ja4: t13i1313h2_f57a46bbacb6_fb48f8b98a29ja4: t13i1314h2_f57a46bbacb6_3b244d8fbcc8ja4: t13i3111h1_e8f1e7e78f70_d41ae481755eja4: t13i1515h2_8daaf6152771_02713d6af862
Sample request paths observed
- /api/v2/files.rar
- /api/v2/files.tar.gz
- /api/v2/files.tgz
- /api/v2/files.tar
- /api/v2/files.tar.bz2
- /api/v2/files.zip
- /api/v2/files.tar.xz
- /api/v1/auto_login
- /api/v2/files.gz
- /api/v2/files.7z