Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mlflow — Vulnerabilities & Security Advisories 78

Browse all 78 CVE security advisories affecting mlflow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MLflow is an open-source platform designed for the machine learning lifecycle, facilitating experiment tracking, reproducibility, and deployment. Despite its utility, the software has accumulated sixty-one Common Vulnerabilities and Exposures (CVEs), indicating significant historical security debt. The most prevalent vulnerability classes involve server-side request forgery, insecure direct object references, and cross-site scripting, often stemming from inadequate input validation in its web interface. Additionally, several issues relate to improper access control, allowing unauthorized users to manipulate experiment data or execute arbitrary code through crafted requests. While no single catastrophic breach has publicly defined its history, the high volume of CVEs suggests systemic weaknesses in authentication and session management. These flaws primarily impact the integrity and confidentiality of machine learning workflows, requiring rigorous patching and secure configuration by administrators to mitigate risks associated with its widely adopted tracking and model serving components.

Found 55 results / 78 Clear Filters
Top products by mlflow: mlflow/mlflow MLflow
CVE ID Title CVSS Severity Published
CVE-2026-8147 Authorization Bypass in mlflow/mlflow — mlflow/mlflow CWE-284 - - 2026-07-02
CVE-2026-4035 Environment Variable Resolution Vulnerability in mlflow/mlflow — mlflow/mlflow CWE-201 - - 2026-06-03
CVE-2026-3198 Improper Access Control in mlflow/mlflow — mlflow/mlflow CWE-284 - - 2026-06-02
CVE-2026-2651 Missing Authorization Validation in mlflow/mlflow — mlflow/mlflow CWE-862 - - 2026-05-25
CVE-2026-2734 Authorization Bypass in SearchModelVersions in mlflow/mlflow — mlflow/mlflow CWE-284 - - 2026-05-21
CVE-2026-2611 Improper Origin Validation in mlflow/mlflow — mlflow/mlflow CWE-346 - - 2026-05-19
CVE-2026-4137 Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow — mlflow/mlflow CWE-378 - - 2026-05-18
CVE-2026-2652 Authentication Bypass in mlflow/mlflow — mlflow/mlflow CWE-305 - - 2026-05-15
CVE-2026-2614 Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow — mlflow/mlflow CWE-22 - - 2026-05-11
CVE-2026-2393 Server-Side Request Forgery (SSRF) in mlflow/mlflow — mlflow/mlflow CWE-918 - - 2026-05-11
CVE-2026-0545 Missing Authentication for Critical Function in mlflow/mlflow — mlflow/mlflow CWE-306 9.8AI Critical AI 2026-04-03
CVE-2026-0596 Command Injection in mlflow/mlflow — mlflow/mlflow CWE-78 7.8 - 2026-03-31
CVE-2025-15379 Command Injection in mlflow/mlflow — mlflow/mlflow CWE-77 8.8 - 2026-03-30
CVE-2025-15036 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow CWE-29 8.4 - 2026-03-30
CVE-2025-15381 Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow — mlflow/mlflow CWE-200 5.4 - 2026-03-27
CVE-2025-15031 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow CWE-22 7.8 - 2026-03-18
CVE-2025-14287 Command Injection in mlflow/mlflow — mlflow/mlflow CWE-94 9.8 - 2026-03-15
CVE-2025-10279 Privilege Escalation in mlflow/mlflow — mlflow/mlflow CWE-379 7.0AI High AI 2026-02-02
CVE-2025-14279 DNS Rebinding Vulnerability in mlflow/mlflow — mlflow/mlflow CWE-346 8.8AI High AI 2026-01-12
CVE-2025-0453 Denial of Service through Batched Queries in GraphQL in mlflow/mlflow — mlflow/mlflow CWE-410 7.5 - 2025-03-20
CVE-2025-1473 CSRF in mlflow/mlflow — mlflow/mlflow CWE-352 8.8 - 2025-03-20
CVE-2025-1474 Weak Password Requirements in mlflow/mlflow — mlflow/mlflow CWE-521 9.8 - 2025-03-20
CVE-2024-8859 Path Traversal in mlflow/mlflow — mlflow/mlflow CWE-29 7.5 - 2025-03-20
CVE-2024-6838 Uncontrolled Resource Consumption in mlflow/mlflow — mlflow/mlflow CWE-400 8.2 - 2025-03-20
CVE-2024-2928 Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow — mlflow/mlflow CWE-29 7.5AI High AI 2024-06-06
CVE-2024-0520 Remote Code Execution due to Full Controlled File Write in mlflow/mlflow — mlflow/mlflow CWE-22 9.8AI Critical AI 2024-06-06
CVE-2024-3099 Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow — mlflow/mlflow CWE-475 8.1AI High AI 2024-06-06
CVE-2024-4263 Improper Access Control in mlflow/mlflow — mlflow/mlflow CWE-284 8.1AI High AI 2024-05-16
CVE-2024-3848 Path Traversal Bypass in mlflow/mlflow — mlflow/mlflow CWE-29 7.5AI High AI 2024-05-16
CVE-2024-3573 Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow — mlflow/mlflow CWE-29 7.5 - 2024-04-16

This page lists every published CVE security advisory associated with mlflow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.