Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mlflow.
- CVE-2026-96804CVE-2026-968048.8
- CVE-2026-96775MLflow dspy bypasses pickle deserialization control8.8
- CVE-2026-79721Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when load...
- CVE-2026-69146MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth6.5
- CVE-2026-69148MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id7.1
- CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)KEV9.3
- CVE-2026-71211mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint7.1
- CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
- CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
- CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
- CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
- CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
- CVE-2026-2611Improper Origin Validation in mlflow/mlflow9.6
- CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow7.8
- CVE-2026-2652Authentication Bypass in mlflow/mlflow8.6