PulseAugur
EN
LIVE 22:23:05

AgentGateway config flaw mirrors football rule; Langflow hit by critical CVE

An advisory from AgentGateway revealed a security vulnerability in its configuration, specifically affecting stateful setups with multiple backends. The issue, present before version 1.4.0, allowed callers to bypass authorization rules by manipulating session IDs and route policies. This vulnerability is analogous to a rule in football (soccer) that prevents goalkeepers from handling back-passes, a rule implemented in 1992 to prevent time-wasting. The problem was identified by @0dd and fixed in AgentGateway version 1.4.0, with version 1.4.1 currently available. Separately, a critical vulnerability (CVE-2026-33017) with a CVSS score of 9.8 was found in Langflow, an open-source AI orchestration framework, allowing unauthenticated access to preview routes. AI

IMPACT Highlights security risks in AI agent infrastructure and orchestration frameworks, emphasizing the need for robust configuration and authorization.

RANK_REASON The cluster discusses security vulnerabilities in specific software tools (AgentGateway and Langflow) rather than a core AI model release or research.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

AgentGateway config flaw mirrors football rule; Langflow hit by critical CVE

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Neeraj Kumar Singh Beshane ·

    The Goalkeeper Rule Your Agent Gateway Forgot

    <p><em>New here? Securing the Agentic Stack is a weekly operator read on AI and security, mapped to one stable six-layer model. Start with the six-layer spine.</em></p> <p>On July 19, Spain lifted the World Cup in New Jersey, and across those 104 matches a goalkeeper somewhere pi…