MLflow
Mlflow · 18 CVEs
CVE-2026-96804
Sep 23, 2026
MLflow dspy bypasses pickle deserialization control
Sep 23, 2026
mlflow: MLflow: Arbitrary code execution via maliciously crafted model artifact
Sep 8, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirec…
Aug 17, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Aug 17, 2026
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
Aug 17, 2026
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
Aug 5, 2026
MLflow Experiment-scoped Label Schema CRUD API authorization
Jun 28, 2026
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
Jun 4, 2026
Authorization Bypass in MLflow AJAX Endpoint
Apr 7, 2026
Stored XSS via unsafe YAML parsing in MLflow
Apr 7, 2026
MLflow Use of Default Password Authentication Bypass Vulnerability
Feb 20, 2026
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
Feb 20, 2026
MLflow Weak Password Requirements Authentication Bypass Vulnerability
Oct 29, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
Oct 29, 2025
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciou…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enablin…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabl…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enablin…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enablin…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…
Jun 4, 2024
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…
Jun 4, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-96804 | CVE-2026-96804 | HIGH | 0.42% | Sep 23, 2026 |
| CVE-2026-96775 | MLflow dspy bypasses pickle deserialization control | HIGH | 0.39% | Sep 23, 2026 |
| CVE-2026-79721 | mlflow: MLflow: Arbitrary code execution via maliciously crafted model artifact | HIGH | 0.47% | Sep 8, 2026 |
| CVE-2026-64849 KEV | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | CRITICAL | 9.84% | Aug 17, 2026 |
| CVE-2026-69146 | MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth | MEDIUM | 0.39% | Aug 17, 2026 |
| CVE-2026-69148 | MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id | HIGH | 0.37% | Aug 17, 2026 |
| CVE-2026-71211 | mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint | HIGH | 0.29% | Aug 5, 2026 |
| CVE-2026-13484 | MLflow Experiment-scoped Label Schema CRUD API authorization | LOW | 0.50% | Jun 28, 2026 |
| CVE-2026-10803 | MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash | LOW | 0.10% | Jun 4, 2026 |
| CVE-2026-33866 | Authorization Bypass in MLflow AJAX Endpoint | MEDIUM | 0.37% | Apr 7, 2026 |
| CVE-2026-33865 | Stored XSS via unsafe YAML parsing in MLflow | MEDIUM | 0.30% | Apr 7, 2026 |
| CVE-2026-2635 | MLflow Use of Default Password Authentication Bypass Vulnerability | HIGH | 1.21% | Feb 20, 2026 |
| CVE-2026-2033 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | HIGH | 1.69% | Feb 20, 2026 |
| CVE-2025-11200 | MLflow Weak Password Requirements Authentication Bypass Vulnerability | CRITICAL | 1.44% | Oct 29, 2025 |
| CVE-2025-11201 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability | CRITICAL | 26.45% | Oct 29, 2025 |
| CVE-2024-37061 | Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitra… | HIGH | 0.88% | Jun 4, 2024 |
| CVE-2024-37060 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execut… | HIGH | 0.78% | Jun 4, 2024 |
| CVE-2024-37059 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37058 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentE… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37057 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow mo… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37056 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37055 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37054 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to… | HIGH | 0.70% | Jun 4, 2024 |
| CVE-2024-37053 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn mod… | HIGH | 0.62% | Jun 4, 2024 |
| CVE-2024-37052 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn mod… | HIGH | 0.66% | Jun 4, 2024 |
Showing 1 to 18 of 18 CVEs