Mlflow
88 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Mlflow, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
Mlflow CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 5 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 2 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 3 |
| 2026-03 | 6 |
| 2026-04 | 3 |
| 2026-05 | 7 |
| 2026-06 | 4 |
| 2026-07 | 1 |
| 2026-08 | 4 |
| 2026-09 | 4 |
Severity
How the 88 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical17
- High54
- Medium12
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Mlflow.
- CVE-2026-96804CVE-2026-968048.8
- CVE-2026-96775MLflow dspy bypasses pickle deserialization control8.8
- CVE-2026-79721Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when load...—
- GHSA-gqvg-gmmx-x4hmMLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact—
- CVE-2026-69146MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth6.5
- CVE-2026-69148MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id7.1
- CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)9.3
- CVE-2026-71211mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint7.1
- CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
- CVE-2026-13484MLflow Experiment-scoped Label Schema CRUD API authorization5.0
- CVE-2026-10803MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash3.6
- CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
- CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
- CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
- CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
Product grouping is registry-driven, with AI assist and human review. How it works