MLflowGHSA-49m6-vrr9-2cqm
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.9CVE-2025-0453 · Published Mar 20, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | <= 2.17.2 | No fix yet |
Details and references
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2024-6838Medium5.3no fix yet | Medium5.3 | No fix yet |
| Mar 202025 | MLflow has a Local File Read/Path Traversal in dbfs CVE-2024-8859High7.5fixed in 2.17.0rc0 | High7.5 | 2.17.0rc0 |
| Mar 202025 | MLflow has Weak Password Requirements CVE-2025-1474Low3.8fixed in 2.19.0 | Low3.8 | 2.19.0 |
| Mar 202025 | MLflow Cross-Site Request Forgery (CSRF) vulnerability CVE-2025-1473Medium5.4fixed in 2.20.3 | Medium5.4 | 2.20.3 |
| Jun 232025 | MLFlow SSRF via gateway_proxy_handler CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0 | Medium5.8 | 2.22.2, 3.1.0 |
| Nov 252024 | MLflow's excessive directory permissions allow local privilege escalation CVE-2024-27134High7.0fixed in 2.16.0 | High7.0 | 2.16.0 |