Mlflow
40 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.
Mlflow CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-12 | 10 | 0 |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | 6 | 0 |
| 2024-05 | null or fewer | |
| 2024-06 | 12 | 0 |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | 5 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | 7 | 0 |
Products
The products that kept showing up in Mlflow's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Mlflow.
- CVE-2026-96804CVE-2026-968048.8
- CVE-2026-96775MLflow dspy bypasses pickle deserialization control8.8
- CVE-2026-79721Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when load...—
- CVE-2026-69146MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth6.5
- CVE-2026-69148MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id7.1
- CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)9.3
- CVE-2026-71211mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint7.1
- CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
- CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
- CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
- CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
- CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
- CVE-2026-2611Improper Origin Validation in mlflow/mlflow9.6
- CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow7.8
- CVE-2026-2652Authentication Bypass in mlflow/mlflow8.6
The record
- Peak rank
- #54 in Jun 2024
- Busiest month shown
- Jun 2024, 12 CVEs
- Months with a KEV entry
- 0 since Dec 2023
- Monthly snapshots
- 5 since 2023