Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-90535

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 16.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-90535


Contact Us

Shodan ® - All rights reserved