Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 12 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption. | |
| Title | Flowise before 3.1.4 Denial of Service via text-to-speech/abort | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T16:04:39.559Z
Reserved: 2026-09-12T11:12:50.791Z
Link: CVE-2026-90535
Updated: 2026-09-14T16:04:34.976Z
Status : Awaiting Analysis
Published: 2026-09-12T13:16:51.380
Modified: 2026-09-14T21:08:51.177
Link: CVE-2026-90535
No data.
OpenCVE Enrichment
Updated: 2026-09-14T16:30:05Z
-
CWE-862
Missing Authorization