MLflowGHSA-pgqp-8h46-6x4j
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
High8.1CVE-2025-14279 · Published Jan 12, 2026 · updated Sep 10, 2026
MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against REST endpoints. An attacker can query, update, and delete experiments via the affected endpoints, leading to potential data exfiltration, destruction, or manipulation. The issue is resolved in version 3.5.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 3.5.0 | 3.5.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-346
- Also known as
- BIT-mlflow-2025-14279, CVE-2025-14279, PYSEC-2026-1656
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 27 | MLFlow allows Tracing + Assessments Access | High8.1 | No fix yet |
| Mar 19 | Arbitrary file write via tar traversal in mlflow | High8.1 | 3.9.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py | High7.5 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | High8.1 | 3.8.0rc0 |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability | Critical9.8 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions | High7.0 | 3.4.0rc0 |