MLflowGHSA-6xj8-rrqx-r4cv
MLflow Weak Password Requirements Authentication Bypass Vulnerability
High8.1CVE-2025-11200 · Published Oct 29, 2025 · updated Jul 7, 2026
MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26916.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.22.0rc0 | 2.22.0rc0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-521
- Also known as
- BIT-mlflow-2025-11200, CVE-2025-11200, PYSEC-2026-1642
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | High8.1 | 3.8.0rc0 |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability | Critical9.8 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions | High7.0 | 3.4.0rc0 |
| Jan 12 | MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation | High8.1 | 3.5.0 |
| Oct 292025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability | High8.1 | 2.22.4+1 more |
| Jun 232025 | MLFlow SSRF via gateway_proxy_handler | Medium5.8 | 2.22.2+1 more |