CVE-2026-41278·Docker vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revealed this is worse than initially assessed: the sanitizeFlowDataForPublicEndpoint function does NOT exist in the released v3.0.13 Docker image. Both public-chatflows AND public-chatbotConfig return completely raw flowData including credential IDs, plaintext API keys, and password-type fields. This vulnerability is fixed in 3.1.0.
- Severity
- high
- Software
- Docker
- Fixed in
- 3.1.0
- Published
- 2026-04-23
Affected versions
Until: 3.1.0
Fixed in: 3.1.0
How to fix this CVE
Update Docker to version 3.1.0 or later to remediate the credential exposure vulnerability in the public chatflow endpoint. The vulnerable versions expose sensitive information including API keys, passwords, and credential IDs without proper sanitization. Immediately patch all Docker installations running versions prior to 3.1.0, then audit your Flowise instances for any unauthorized access to public chatflow endpoints.
sudo dnf update docker-ce && sudo systemctl restart dockerDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET /api/v1/public-chatflows/[a-zA-Z0-9_-]+ HTTP|GET /api/v1/public-chatbotConfig/[a-zA-Z0-9_-]+ HTTPWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to restrict GET requests to `/api/v1/public-chatflows/*` and `/api/v1/public-chatbotConfig/*` endpoints unless they originate from trusted sources. Add response filtering to strip credential fields (API keys, passwords, credential IDs) before they reach clients, as a temporary measure until Docker is patched.How to check if you are affected
- Run `docker --version` to confirm the installed Docker version; versions prior to 3.1.0 are vulnerable.
- Check if Flowise is running: `docker ps | grep flowise` and note the image tag; vulnerable tags are v3.0.13 and earlier.
- Search Docker logs for GET requests to `/api/v1/public-chatflows/:id` or `/api/v1/public-chatbotConfig`: `docker logs <container-id> | grep -E '(public-chatflows|public-chatbotConfig)'`
- Verify the patch by running `docker inspect <image-id> | grep -i version` and confirming the version is 3.1.0 or higher.
FAQ
What is CVE-2026-41278?
CVE-2026-41278 is a credential exposure vulnerability in Docker/Flowise where the public chatflow endpoint fails to sanitize sensitive data, returning raw credentials including API keys and passwords to unauthenticated users.
Is CVE-2026-41278 being actively exploited?
No, there is no evidence of active exploitation or publicly available exploits for this vulnerability at this time, though the ease of access via HTTP requests makes exploitation trivial.
What versions of Docker are affected by CVE-2026-41278?
All versions of Docker/Flowise prior to version 3.1.0 are affected; the vulnerability is present in v3.0.13 and all earlier releases.
How do I check if my server is vulnerable to CVE-2026-41278?
Run `docker --version` to check your Docker version; if it returns a version lower than 3.1.0, your installation is vulnerable. Also verify with `docker image ls | grep flowise` to see if vulnerable Flowise images are present.
Does Defensia detect CVE-2026-41278?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-41278 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-41278. Free for 1 server.
Get started free