Skip to content
MLRunGHSA-phx2-3w66-h4pw

mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption

Low3.6CVE-2026-10766 · Published Jun 3, 2026 · updated Jul 23, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlrun
PyPI
<= 1.12.0rc3No fix yet
Details and references

A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Handler. The manipulation leads to use of weak hash. The attack can only be performed from a local environment. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-327
Also known as
CVE-2026-10766, PYSEC-2026-3487

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.