CVE-2026-56272
EUVD-2026-3874824.06.2026, 13:16
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.