CVE Tools

Lfprojects

68 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.

Lfprojects CVEs per month

Dec 2023 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Lfprojects CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-12110
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-0460
2024-05null or fewer
2024-06130
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-0350
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-0270
2026-03100
2026-0460
2026-05100

Products

The products that kept showing up in Lfprojects's monthly top three, with their CVEs summed over those months.

  1. Mlflow528 months
  2. Mcp Registry31 month
  3. Valkey31 month
  4. Mcp Go Sdk22 months
  5. Agentgateway11 month
  6. Mcp Java Sdk11 month
  7. Valkey-bloom11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Lfprojects.

  1. CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)9.3
  2. CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validation8.1
  3. CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks7.6
  4. CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal7.1
  5. CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
  6. CVE-2026-13484MLflow Experiment-scoped Label Schema CRUD API authorization5.0
  7. CVE-2026-10803MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash3.6
  8. CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
  9. CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
  10. CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
  11. CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
  12. CVE-2026-2611Improper Origin Validation in mlflow/mlflow9.6
  13. CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow7.8
  14. CVE-2026-2652Authentication Bypass in mlflow/mlflow8.6
  15. CVE-2026-44428MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience4.7

The record

Peak rank
#48 in Jun 2024
Busiest month shown
Jun 2024, 13 CVEs
Months with a KEV entry
0 since Dec 2023
Monthly snapshots
8 since 2023
Lfprojects's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store