Databricks security advisories
82 advisories across MLflow
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifact GHSA-gqvg-gmmx-x4hmHigh8.8fixed in 3.15.0 | High8.8 | 3.15.0 |
| Aug 17 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CVE-2026-64849Critical9.3fixed in 3.15.0 | Critical9.3 | 3.15.0 |
| Aug 5 | MLflow AI Gateway permits SSRF through an unvalidated api_base CVE-2026-71211High7.1no fix yet | High7.1 | No fix yet |
| Jul 2 | MLflow: trace API endpoints lack proper authorization validators CVE-2026-8147High8.1fixed in 3.13.0rc0 | High8.1 | 3.13.0rc0 |
| Jun 4 | MLflow: Deterministic sampling in dataset digest enables predictable collisions CVE-2026-10803Low3.6fixed in 3.10.1 | Low3.6 | 3.10.1 |
| Jun 3 | MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration CVE-2026-4035Critical9.1fixed in 3.11.0 | Critical9.1 | 3.11.0 |
| Jun 2 | MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions CVE-2026-3198Medium6.5fixed in 3.11.0rc0 | Medium6.5 | 3.11.0rc0 |
| May 26 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled CVE-2026-2651Critical9.0fixed in 3.11.0rc1 | Critical9.0 | 3.11.0rc1 |
| May 21 | MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks CVE-2026-2734Medium6.5fixed in 3.10.0 | Medium6.5 | 3.10.0 |
| May 19 | MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution CVE-2026-2611Critical9.6fixed in 3.10.0 | Critical9.6 | 3.10.0 |
| May 18 | MLFlow Creates a Temporary File With Insecure Permissions CVE-2026-4137High7.0fixed in 3.11.0 | High7.0 | 3.11.0 |
| May 15 | MLflow: unauthenticated access to certain FastAPI routes CVE-2026-2652High8.6fixed in 3.11.0 | High8.6 | 3.11.0 |
| May 11 | MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem CVE-2026-2614High7.5fixed in 3.10.0 | High7.5 | 3.10.0 |
| May 11 | MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability CVE-2026-2393High7.1fixed in 3.9.0 | High7.1 | 3.9.0 |
| Apr 7 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint CVE-2026-33866Medium4.3fixed in 3.11.0rc0 | Medium4.3 | 3.11.0rc0 |
| Apr 7 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface CVE-2026-33865Medium5.4fixed in 3.11.1 | Medium5.4 | 3.11.1 |
| Apr 3 | mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization CVE-2026-0545Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 31 | Mlflow: Command Injection when serving models with enable_mlserver=True CVE-2026-0596Critical9.6fixed in 3.9.0 | Critical9.6 | 3.9.0 |
| Mar 30 | MLflow Command Injection vulnerability CVE-2025-15379Critical10.0fixed in 3.8.1 | Critical10.0 | 3.8.1 |
| Mar 30 | MLFlow path traversal vulnerability CVE-2025-15036Critical9.6fixed in 3.9.0rc0 | Critical9.6 | 3.9.0rc0 |
| Mar 27 | MLFlow allows Tracing + Assessments Access CVE-2025-15381High8.1no fix yet | High8.1 | No fix yet |
| Mar 19 | Arbitrary file write via tar traversal in mlflow CVE-2025-15031High8.1fixed in 3.9.0rc0 | High8.1 | 3.9.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py CVE-2025-14287High7.5fixed in 3.8.0rc0 | High7.5 | 3.8.0rc0 |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability CVE-2026-2635Critical9.8fixed in 3.8.0rc0 | Critical9.8 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability CVE-2026-2033High8.1fixed in 3.8.0rc0 | High8.1 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions CVE-2025-10279High7.0fixed in 3.4.0rc0 | High7.0 | 3.4.0rc0 |
| Jan 12 | MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation CVE-2025-14279High8.1fixed in 3.5.0 | High8.1 | 3.5.0 |
| Oct 292025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability CVE-2025-11201High8.1fixed in 2.22.4, 3.0.0 | High8.1 | 2.22.4, 3.0.0 |
| Oct 292025 | MLflow Weak Password Requirements Authentication Bypass Vulnerability CVE-2025-11200High8.1fixed in 2.22.0rc0 | High8.1 | 2.22.0rc0 |
| Jun 232025 | MLFlow SSRF via gateway_proxy_handler CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0 | Medium5.8 | 2.22.2, 3.1.0 |
| Mar 202025 | MLflow has Weak Password Requirements CVE-2025-1474Low3.8fixed in 2.19.0 | Low3.8 | 2.19.0 |
| Mar 202025 | MLflow Cross-Site Request Forgery (CSRF) vulnerability CVE-2025-1473Medium5.4fixed in 2.20.3 | Medium5.4 | 2.20.3 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2025-0453Medium5.9no fix yet | Medium5.9 | No fix yet |
| Mar 202025 | MLflow has a Local File Read/Path Traversal in dbfs CVE-2024-8859High7.5fixed in 2.17.0rc0 | High7.5 | 2.17.0rc0 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2024-6838Medium5.3no fix yet | Medium5.3 | No fix yet |
| Nov 252024 | MLflow's excessive directory permissions allow local privilege escalation CVE-2024-27134High7.0fixed in 2.16.0 | High7.0 | 2.16.0 |
| Jun 62024 | Undefined Behavior in mlflow CVE-2024-3099Medium5.4fixed in 2.11.3 | Medium5.4 | 2.11.3 |
| Jun 62024 | Local File Inclusion in mlflow CVE-2024-2928High7.5fixed in 2.11.3 | High7.5 | 2.11.3 |
| Jun 62024 | Remote code execution in mlflow CVE-2024-0520Critical10.0fixed in 2.9.0 | Critical10.0 | 2.9.0 |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37060High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37058High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37057High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow improper input validation CVE-2024-37061High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37059High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37053High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37052High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37056High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37054High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37055High8.8no fix yet | High8.8 | No fix yet |
| May 162024 | MLflow allows low privilege users to delete any artifact CVE-2024-4263Medium5.4fixed in 2.10.1 | Medium5.4 | 2.10.1 |
| May 162024 | MLflow has a Local File Read/Path Traversal bypass CVE-2024-3848High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-3573Critical9.3fixed in 2.10.0 | Critical9.3 | 2.10.0 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1560High8.1no fix yet | High8.1 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1593High7.5no fix yet | High7.5 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1558High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1594High7.5no fix yet | High7.5 | No fix yet |
| Apr 162024 | mlflow Path Traversal vulnerability CVE-2024-1483High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Feb 242024 | MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution CVE-2024-27133Critical9.6fixed in 2.10.0 | Critical9.6 | 2.10.0 |
| Feb 242024 | Cross-site Scripting in MLFlow CVE-2024-27132Critical9.6fixed in 2.10.0 | Critical9.6 | 2.10.0 |
| Dec 202023 | MLflow Server-Side Request Forgery (SSRF) CVE-2023-6974Critical9.8fixed in 2.9.2 | Critical9.8 | 2.9.2 |
The newest 60. Each project page has the full list.
About Databricks
Databricks, Inc. is an American data and artificial intelligence software company headquartered in San Francisco, California. It was founded in 2013 by the original creators of Apache Spark at the University of California, Berkeley.
Elsewhere on fru.dev: Acquisitions · Funding · Paydays · Releases · Repos · TechConf