MLflow

Mlflow · 18 CVEs

CVE-2026-96804
HIGH

CVE-2026-96804

Sep 23, 2026

CVE-2026-96775
HIGH

MLflow dspy bypasses pickle deserialization control

Sep 23, 2026

CVE-2026-79721
HIGH

mlflow: MLflow: Arbitrary code execution via maliciously crafted model artifact

Sep 8, 2026

CVE-2026-64849
KEV CRITICAL

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirec…

Aug 17, 2026

CVE-2026-69146
MEDIUM

MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

Aug 17, 2026

CVE-2026-69148
HIGH

MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id

Aug 17, 2026

CVE-2026-71211
HIGH

mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint

Aug 5, 2026

CVE-2026-13484
LOW

MLflow Experiment-scoped Label Schema CRUD API authorization

Jun 28, 2026

CVE-2026-10803
LOW

MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash

Jun 4, 2026

CVE-2026-33866
MEDIUM

Authorization Bypass in MLflow AJAX Endpoint

Apr 7, 2026

CVE-2026-33865
MEDIUM

Stored XSS via unsafe YAML parsing in MLflow

Apr 7, 2026

CVE-2026-2635
HIGH

MLflow Use of Default Password Authentication Bypass Vulnerability

Feb 20, 2026

CVE-2026-2033
HIGH

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

Feb 20, 2026

CVE-2025-11200
CRITICAL

MLflow Weak Password Requirements Authentication Bypass Vulnerability

Oct 29, 2025

CVE-2025-11201
CRITICAL

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

Oct 29, 2025

CVE-2024-37061
HIGH

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciou…

Jun 4, 2024

CVE-2024-37060
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enablin…

Jun 4, 2024

CVE-2024-37059
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling…

Jun 4, 2024

CVE-2024-37058
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling…

Jun 4, 2024

CVE-2024-37057
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabl…

Jun 4, 2024

CVE-2024-37056
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enablin…

Jun 4, 2024

CVE-2024-37055
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enablin…

Jun 4, 2024

CVE-2024-37054
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling…

Jun 4, 2024

CVE-2024-37053
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…

Jun 4, 2024

CVE-2024-37052
HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…

Jun 4, 2024

Showing 1 to 18 of 18 CVEs