Retour à la veille

CVE-2026-90535

Publié : 12 septembre 2026
Modifié : 12 septembre 2026
Lien officiel NVD

Description détaillée

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.

Références et Patchs

Dernières Vulnérabilités