Skip to content
MLflowGHSA-wxj7-3fx5-pp9m

MLFlow SSRF via gateway_proxy_handler

Medium5.8CVE-2025-52967 · Published Jun 23, 2025 · updated Sep 25, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
>= 3.0.0rc0, < 3.1.03.1.0
< 2.22.22.22.2
Details and references

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
BIT-mlflow-2025-52967, CVE-2025-52967, PYSEC-2025-52

More MLflow advisories

All MLflow
DateAdvisory
Mar 202025MLflow has Weak Password Requirements
CVE-2025-1474Low3.8fixed in 2.19.0
Mar 202025MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2025-1473Medium5.4fixed in 2.20.3
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2025-0453Medium5.9no fix yet
Mar 202025MLflow has a Local File Read/Path Traversal in dbfs
CVE-2024-8859High7.5fixed in 2.17.0rc0
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-6838Medium5.3no fix yet
Oct 292025MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CVE-2025-11201High8.1fixed in 2.22.4, 3.0.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.