Mlflow
Lfprojects · 77 CVEs
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirec…
Aug 17, 2026
Authorization Bypass in mlflow/mlflow
Jul 2, 2026
MLflow Experiment-scoped Label Schema CRUD API authorization
Jun 28, 2026
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
Jun 4, 2026
Environment Variable Resolution Vulnerability in mlflow/mlflow
Jun 3, 2026
Improper Access Control in mlflow/mlflow
Jun 2, 2026
Missing Authorization Validation in mlflow/mlflow
May 25, 2026
Authorization Bypass in SearchModelVersions in mlflow/mlflow
May 21, 2026
Improper Origin Validation in mlflow/mlflow
May 19, 2026
Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
May 18, 2026
Authentication Bypass in mlflow/mlflow
May 15, 2026
Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow
May 11, 2026
Server-Side Request Forgery (SSRF) in mlflow/mlflow
May 11, 2026
Authorization Bypass in MLflow AJAX Endpoint
Apr 7, 2026
Stored XSS via unsafe YAML parsing in MLflow
Apr 7, 2026
Missing Authentication for Critical Function in mlflow/mlflow
Apr 3, 2026
Command Injection in mlflow/mlflow
Mar 31, 2026
Command Injection in mlflow/mlflow
Mar 30, 2026
Path Traversal Vulnerability in mlflow/mlflow
Mar 30, 2026
Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow
Mar 27, 2026
Path Traversal Vulnerability in mlflow/mlflow
Mar 18, 2026
Command Injection in mlflow/mlflow
Mar 15, 2026
Privilege Escalation in mlflow/mlflow
Feb 2, 2026
DNS Rebinding Vulnerability in mlflow/mlflow
Jan 12, 2026
MLflow Weak Password Requirements Authentication Bypass Vulnerability
Oct 29, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-64849 KEV | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | CRITICAL | 9.84% | Aug 17, 2026 |
| CVE-2026-8147 | Authorization Bypass in mlflow/mlflow | HIGH | 0.55% | Jul 2, 2026 |
| CVE-2026-13484 | MLflow Experiment-scoped Label Schema CRUD API authorization | LOW | 0.50% | Jun 28, 2026 |
| CVE-2026-10803 | MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash | LOW | 0.10% | Jun 4, 2026 |
| CVE-2026-4035 | Environment Variable Resolution Vulnerability in mlflow/mlflow | HIGH | 0.66% | Jun 3, 2026 |
| CVE-2026-3198 | Improper Access Control in mlflow/mlflow | MEDIUM | 0.36% | Jun 2, 2026 |
| CVE-2026-2651 | Missing Authorization Validation in mlflow/mlflow | CRITICAL | 0.54% | May 25, 2026 |
| CVE-2026-2734 | Authorization Bypass in SearchModelVersions in mlflow/mlflow | MEDIUM | 0.50% | May 21, 2026 |
| CVE-2026-2611 | Improper Origin Validation in mlflow/mlflow | CRITICAL | 0.41% | May 19, 2026 |
| CVE-2026-4137 | Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow | HIGH | 0.16% | May 18, 2026 |
| CVE-2026-2652 | Authentication Bypass in mlflow/mlflow | HIGH | 1.41% | May 15, 2026 |
| CVE-2026-2614 | Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow | HIGH | 3.21% | May 11, 2026 |
| CVE-2026-2393 | Server-Side Request Forgery (SSRF) in mlflow/mlflow | HIGH | 0.29% | May 11, 2026 |
| CVE-2026-33866 | Authorization Bypass in MLflow AJAX Endpoint | MEDIUM | 0.37% | Apr 7, 2026 |
| CVE-2026-33865 | Stored XSS via unsafe YAML parsing in MLflow | MEDIUM | 0.30% | Apr 7, 2026 |
| CVE-2026-0545 | Missing Authentication for Critical Function in mlflow/mlflow | CRITICAL | 4.39% | Apr 3, 2026 |
| CVE-2026-0596 | Command Injection in mlflow/mlflow | HIGH | 1.33% | Mar 31, 2026 |
| CVE-2025-15379 | Command Injection in mlflow/mlflow | CRITICAL | 2.36% | Mar 30, 2026 |
| CVE-2025-15036 | Path Traversal Vulnerability in mlflow/mlflow | CRITICAL | 0.58% | Mar 30, 2026 |
| CVE-2025-15381 | Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow | HIGH | 0.33% | Mar 27, 2026 |
| CVE-2025-15031 | Path Traversal Vulnerability in mlflow/mlflow | CRITICAL | 0.85% | Mar 18, 2026 |
| CVE-2025-14287 | Command Injection in mlflow/mlflow | HIGH | 1.46% | Mar 15, 2026 |
| CVE-2025-10279 | Privilege Escalation in mlflow/mlflow | HIGH | 0.24% | Feb 2, 2026 |
| CVE-2025-14279 | DNS Rebinding Vulnerability in mlflow/mlflow | HIGH | 0.21% | Jan 12, 2026 |
| CVE-2025-11200 | MLflow Weak Password Requirements Authentication Bypass Vulnerability | CRITICAL | 1.44% | Oct 29, 2025 |
Showing 1 to 25 of 77 CVEs