MLflowGHSA-5qmp-p3c4-72qj
MLflow: Deterministic sampling in dataset digest enables predictable collisions
Low3.6CVE-2026-10803 · Published Jun 4, 2026 · updated Jul 15, 2026
A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 3.10.1 | 3.10.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-327
- Also known as
- BIT-mlflow-2026-10803, CVE-2026-10803, PYSEC-2026-195
- nvd.nist.gov/vuln/detail/CVE-2026-10803
- github.com/mlflow/mlflow/issues/22419
- github.com/mlflow/mlflow/pull/22420
- github.com/mlflow/mlflow
- github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-195.yaml
- vuldb.com/cve/CVE-2026-10803
- vuldb.com/submit/831462
- vuldb.com/vuln/368252
- vuldb.com/vuln/368252/cti
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 3 | MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration | Critical9.1 | 3.11.0 |
| Jun 2 | MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions | Medium6.5 | 3.11.0rc0 |
| May 26 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled | Critical9.0 | 3.11.0rc1 |
| May 21 | MLflow: information disclosure | Medium6.5 | 3.10.0 |
| May 19 | MLflow: origin validation error | Critical9.6 | 3.10.0 |
| May 18 | MLFlow Creates a Temporary File With Insecure Permissions | High7.0 | 3.11.0 |