Skip to content
MLflowGHSA-q3gw-8236-5jw4

MLflow Uncontrolled Resource Consumption vulnerability

Medium5.3CVE-2024-6838 · Published Mar 20, 2025 · updated Jul 7, 2026

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become unresponsive, leading to a potential denial of service. Additionally, there is no character limit in the `artifact_location` parameter while creating the experiment.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
<= 2.13.2No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
BIT-mlflow-2024-6838, CVE-2024-6838, PYSEC-2026-1658

More MLflow advisories

All MLflow
Advisory
MLFlow SSRF via gateway_proxy_handler
Medium5.8Jun 23, 2025
MLflow has Weak Password Requirements
Low3.8Mar 20, 2025
MLflow Cross-Site Request Forgery (CSRF) vulnerability
Medium5.4Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.9Mar 20, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High7.5Mar 20, 2025
MLflow's excessive directory permissions allow local privilege escalation
High7.0Nov 25, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.