Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mlflow — Vulnerabilities & Security Advisories 78

Browse all 78 CVE security advisories affecting mlflow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MLflow is an open-source platform designed for the machine learning lifecycle, facilitating experiment tracking, reproducibility, and deployment. Despite its utility, the software has accumulated sixty-one Common Vulnerabilities and Exposures (CVEs), indicating significant historical security debt. The most prevalent vulnerability classes involve server-side request forgery, insecure direct object references, and cross-site scripting, often stemming from inadequate input validation in its web interface. Additionally, several issues relate to improper access control, allowing unauthorized users to manipulate experiment data or execute arbitrary code through crafted requests. While no single catastrophic breach has publicly defined its history, the high volume of CVEs suggests systemic weaknesses in authentication and session management. These flaws primarily impact the integrity and confidentiality of machine learning workflows, requiring rigorous patching and secure configuration by administrators to mitigate risks associated with its widely adopted tracking and model serving components.

Found 23 results / 78 Clear Filters
Top products by mlflow: mlflow/mlflow MLflow
CVE ID Title CVSS Severity Published
CVE-2026-96804 CVE-2026-96804 — MLflow - - 2026-09-23
CVE-2026-96775 MLflow dspy bypasses pickle deserialization control — MLflow - - 2026-09-23
CVE-2026-79721 MLflow 软件供应链问题漏洞 — mlflow CWE-829 8.6 High 2026-09-08
CVE-2026-69146 MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth — mlflow CWE-862 6.5 Medium 2026-08-17
CVE-2026-69148 MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id — mlflow CWE-862 7.1 High 2026-08-17
CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) — mlflow CWE-918 9.3 Critical 2026-08-17
CVE-2026-71211 mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint — mlflow CWE-918 7.1 High 2026-08-05
CVE-2026-33866 Authorization Bypass in MLflow AJAX Endpoint — Mlflow CWE-862 4.3AI Medium AI 2026-04-07
CVE-2026-33865 Stored XSS via unsafe YAML parsing in MLflow — Mlflow CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability — MLflow CWE-1393 9.8AI Critical AI 2026-02-20
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability — MLflow CWE-22 9.8AI Critical AI 2026-02-20
CVE-2025-11200 MLflow Weak Password Requirements Authentication Bypass Vulnerability — MLflow CWE-521 9.8AI Critical AI 2025-10-29
CVE-2025-11201 MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability — MLflow CWE-22 9.8AI Critical AI 2025-10-29
CVE-2024-37061 MLflow 安全漏洞 — MLflow CWE-94 8.8 High 2024-06-04
CVE-2024-37060 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37059 Mlflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37058 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37057 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37056 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37055 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37054 MLflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37053 Mlflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04
CVE-2024-37052 Mlflow 安全漏洞 — MLflow CWE-502 8.8 High 2024-06-04

This page lists every published CVE security advisory associated with mlflow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.