Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption. | |
| Title | Flowise before 3.1.4 Denial of Service via text-to-speech/abort | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T12:08:44.062Z
Reserved: 2026-09-12T11:12:50.791Z
Link: CVE-2026-90535
No data.
Status : Received
Published: 2026-09-12T13:16:51.380
Modified: 2026-09-12T13:16:51.380
Link: CVE-2026-90535
No data.
OpenCVE Enrichment
Updated: 2026-09-12T16:45:07Z