Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MLflow — Vulnerabilities & Security Advisories 26

All 26 CVE vulnerabilities found in MLflow, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting MLflow, an open-source platform for the machine learning lifecycle. It collects disclosures related to injection flaws, path traversal issues, and improper input validation, covering the time range from the product's initial release through the most recent advisory. Readers can use this hub to track a vendor's published advisories, understand a specific weakness class, and review the full vulnerability history of this data science framework. The entries are organized by CVE identifier and severity rating, allowing security teams to correlate incident reports with corresponding patches. No marketing language is used; the focus remains on factual reporting. Each record includes the affected versions, the specific misconfiguration or code pattern involved, and the remediation path. This enables engineers to map historical exposure windows and verify whether a particular deployment environment was impacted. The collection supports both compliance audits and risk assessment workflows. Users can filter by year, component, or weakness type to isolate relevant threats. The data reflects publicly available information only, ensuring reproducibility and transparency. By centralizing these records, the page reduces the effort required to cross-reference scattered security bulletins. It serves as a neutral reference point for incident response teams investigating potential breaches or evaluating upgrade priorities. The structure prioritizes clarity and direct access to technical details without editorial commentary.

Vendor: MLflow

CVE ID Title CVSS Severity Published
CVE-2026-96804 CVE-2026-96804 - - 2026-09-23
CVE-2026-96775 MLflow dspy bypasses pickle deserialization control - - 2026-09-23
CVE-2026-79721 MLflow 软件供应链问题漏洞 CWE-829 8.6 High 2026-09-08
CVE-2026-69146 MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth CWE-862 6.5 Medium 2026-08-17
CVE-2026-69148 MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id CWE-862 7.1 High 2026-08-17
CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CWE-918 9.3 Critical 2026-08-17
CVE-2026-71211 mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint CWE-918 7.1 High 2026-08-05
CVE-2026-13484 MLflow Experiment-scoped Label Schema CRUD API authorization CWE-862 5.0 Medium 2026-06-28
CVE-2026-10803 MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash CWE-328 3.6 Low 2026-06-04
CVE-2026-33866 Authorization Bypass in MLflow AJAX Endpoint CWE-862 4.3AI Medium AI 2026-04-07
CVE-2026-33865 Stored XSS via unsafe YAML parsing in MLflow CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability CWE-1393 9.8AI Critical AI 2026-02-20
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8AI Critical AI 2026-02-20
CVE-2025-11200 MLflow Weak Password Requirements Authentication Bypass Vulnerability CWE-521 9.8AI Critical AI 2025-10-29
CVE-2025-11201 MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8AI Critical AI 2025-10-29
CVE-2025-52967 MLflow 代码问题漏洞 CWE-918 5.8 Medium 2025-06-23
CVE-2024-37061 MLflow 安全漏洞 CWE-94 8.8 High 2024-06-04
CVE-2024-37060 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37059 Mlflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37058 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37057 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37056 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37055 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37054 MLflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37053 Mlflow 安全漏洞 CWE-502 8.8 High 2024-06-04
CVE-2024-37052 Mlflow 安全漏洞 CWE-502 8.8 High 2024-06-04

All 26 known CVE vulnerabilities affecting MLflow with full Chinese analysis, references, and POCs where available.