Mlflow
This hub aggregates every CVE we track for Mlflow, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
80
CVEs tracked
16
Critical
51
High
0
In CISA KEV
Severity distribution
HIGH51CRITICAL16MEDIUM11LOW2
Monthly trend
0
0
1
0
0
0
5
0
0
1
0
0
0
2
0
0
1
3
6
3
7
4
1
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mlflow.
- CVE-2026-71211mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint7.1
- CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
- CVE-2026-13484MLflow Experiment-scoped Label Schema CRUD API authorization5.0
- CVE-2026-10803MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash3.6
- CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
- CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
- CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
- CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
- CVE-2026-2611Improper Origin Validation in mlflow/mlflow9.6
- CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow7.8
- CVE-2026-2652Authentication Bypass in mlflow/mlflow8.6
- CVE-2026-2614Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow7.5
- CVE-2026-2393Server-Side Request Forgery (SSRF) in mlflow/mlflow7.1
- CVE-2026-33866Authorization Bypass in MLflow AJAX Endpoint4.3
- CVE-2026-33865Stored XSS via unsafe YAML parsing in MLflow5.4
Product normalization is registry-driven with AI assist and human review. How it works