Skip to content
MLflowGHSA-49m6-vrr9-2cqm

MLflow Uncontrolled Resource Consumption vulnerability

Medium5.9CVE-2025-0453 · Published Mar 20, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
<= 2.17.2No fix yet
Details and references

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.

CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-410
Also known as
BIT-mlflow-2025-0453, CVE-2025-0453, PYSEC-2026-1637

More MLflow advisories

All MLflow
DateAdvisory
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-6838Medium5.3no fix yet
Mar 202025MLflow has a Local File Read/Path Traversal in dbfs
CVE-2024-8859High7.5fixed in 2.17.0rc0
Mar 202025MLflow has Weak Password Requirements
CVE-2025-1474Low3.8fixed in 2.19.0
Mar 202025MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2025-1473Medium5.4fixed in 2.20.3
Jun 232025MLFlow SSRF via gateway_proxy_handler
CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0
Nov 252024MLflow's excessive directory permissions allow local privilege escalation
CVE-2024-27134High7.0fixed in 2.16.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.