MLflowGHSA-wxj7-3fx5-pp9m
MLFlow SSRF via gateway_proxy_handler
Medium5.8CVE-2025-52967 · Published Jun 23, 2025 · updated Sep 25, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | >= 3.0.0rc0, < 3.1.0 | 3.1.0 |
| < 2.22.2 | 2.22.2 |
Details and references
gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- BIT-mlflow-2025-52967, CVE-2025-52967, PYSEC-2025-52
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | MLflow has Weak Password Requirements CVE-2025-1474Low3.8fixed in 2.19.0 | Low3.8 | 2.19.0 |
| Mar 202025 | MLflow Cross-Site Request Forgery (CSRF) vulnerability CVE-2025-1473Medium5.4fixed in 2.20.3 | Medium5.4 | 2.20.3 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2025-0453Medium5.9no fix yet | Medium5.9 | No fix yet |
| Mar 202025 | MLflow has a Local File Read/Path Traversal in dbfs CVE-2024-8859High7.5fixed in 2.17.0rc0 | High7.5 | 2.17.0rc0 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2024-6838Medium5.3no fix yet | Medium5.3 | No fix yet |
| Oct 292025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability CVE-2025-11201High8.1fixed in 2.22.4, 3.0.0 | High8.1 | 2.22.4, 3.0.0 |