Skip to content

MLflow security advisories

82 advisories · 24 critical or high in 12 months · latest Sep 1

60 of 82 advisories

DateAdvisory
Sep 1MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifact
GHSA-gqvg-gmmx-x4hmHigh8.8fixed in 3.15.0
Aug 17MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVE-2026-64849Critical9.3fixed in 3.15.0
Aug 5MLflow AI Gateway permits SSRF through an unvalidated api_base
CVE-2026-71211High7.1no fix yet
Jul 2MLflow: trace API endpoints lack proper authorization validators
CVE-2026-8147High8.1fixed in 3.13.0rc0
Jun 4MLflow: Deterministic sampling in dataset digest enables predictable collisions
CVE-2026-10803Low3.6fixed in 3.10.1
Jun 3MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
CVE-2026-4035Critical9.1fixed in 3.11.0
Jun 2MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
CVE-2026-3198Medium6.5fixed in 3.11.0rc0
May 26MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
CVE-2026-2651Critical9.0fixed in 3.11.0rc1
May 21MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-2734Medium6.5fixed in 3.10.0
May 19MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CVE-2026-2611Critical9.6fixed in 3.10.0
May 18MLFlow Creates a Temporary File With Insecure Permissions
CVE-2026-4137High7.0fixed in 3.11.0
May 15MLflow: unauthenticated access to certain FastAPI routes
CVE-2026-2652High8.6fixed in 3.11.0
May 11MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-2614High7.5fixed in 3.10.0
May 11MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-2393High7.1fixed in 3.9.0
Apr 7MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
CVE-2026-33866Medium4.3fixed in 3.11.0rc0
Apr 7MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
CVE-2026-33865Medium5.4fixed in 3.11.1
Apr 3mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
CVE-2026-0545Critical9.1no fix yet
Mar 31Mlflow: Command Injection when serving models with enable_mlserver=True
CVE-2026-0596Critical9.6fixed in 3.9.0
Mar 30MLflow Command Injection vulnerability
CVE-2025-15379Critical10.0fixed in 3.8.1
Mar 30MLFlow path traversal vulnerability
CVE-2025-15036Critical9.6fixed in 3.9.0rc0
Mar 27MLFlow allows Tracing + Assessments Access
CVE-2025-15381High8.1no fix yet
Mar 19Arbitrary file write via tar traversal in mlflow
CVE-2025-15031High8.1fixed in 3.9.0rc0
Mar 16MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2025-14287High7.5fixed in 3.8.0rc0
Feb 21MLflow Use of Default Password Authentication Bypass Vulnerability
CVE-2026-2635Critical9.8fixed in 3.8.0rc0
Feb 21MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
CVE-2026-2033High8.1fixed in 3.8.0rc0
Feb 2mlflow Creates of Temporary File in Directory with Insecure Permissions
CVE-2025-10279High7.0fixed in 3.4.0rc0
Jan 12MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
CVE-2025-14279High8.1fixed in 3.5.0
Oct 292025MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CVE-2025-11201High8.1fixed in 2.22.4, 3.0.0
Oct 292025MLflow Weak Password Requirements Authentication Bypass Vulnerability
CVE-2025-11200High8.1fixed in 2.22.0rc0
Jun 232025MLFlow SSRF via gateway_proxy_handler
CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0
Mar 202025MLflow has Weak Password Requirements
CVE-2025-1474Low3.8fixed in 2.19.0
Mar 202025MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2025-1473Medium5.4fixed in 2.20.3
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2025-0453Medium5.9no fix yet
Mar 202025MLflow has a Local File Read/Path Traversal in dbfs
CVE-2024-8859High7.5fixed in 2.17.0rc0
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-6838Medium5.3no fix yet
Nov 252024MLflow's excessive directory permissions allow local privilege escalation
CVE-2024-27134High7.0fixed in 2.16.0
Jun 62024Undefined Behavior in mlflow
CVE-2024-3099Medium5.4fixed in 2.11.3
Jun 62024Local File Inclusion in mlflow
CVE-2024-2928High7.5fixed in 2.11.3
Jun 62024Remote code execution in mlflow
CVE-2024-0520Critical10.0fixed in 2.9.0
Jun 42024MLFlow unsafe deserialization
CVE-2024-37060High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37058High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37057High8.8no fix yet
Jun 42024MLFlow improper input validation
CVE-2024-37061High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37059High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37053High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37052High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37056High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37054High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37055High8.8no fix yet
May 162024MLflow allows low privilege users to delete any artifact
CVE-2024-4263Medium5.4fixed in 2.10.1
May 162024MLflow has a Local File Read/Path Traversal bypass
CVE-2024-3848High7.5fixed in 2.12.1
Apr 162024mlflow vulnerable to Path Traversal
CVE-2024-3573Critical9.3fixed in 2.10.0
Apr 162024mlflow vulnerable to Path Traversal
CVE-2024-1560High8.1no fix yet
Apr 162024mlflow vulnerable to Path Traversal
CVE-2024-1593High7.5no fix yet
Apr 162024mlflow vulnerable to Path Traversal
CVE-2024-1558High7.5fixed in 2.12.1
Apr 162024mlflow vulnerable to Path Traversal
CVE-2024-1594High7.5no fix yet
Apr 162024mlflow Path Traversal vulnerability
CVE-2024-1483High7.5fixed in 2.12.1
Feb 242024MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
CVE-2024-27133Critical9.6fixed in 2.10.0
Feb 242024Cross-site Scripting in MLFlow
CVE-2024-27132Critical9.6fixed in 2.10.0
Dec 202023MLflow Server-Side Request Forgery (SSRF)
CVE-2023-6974Critical9.8fixed in 2.9.2
About MLflow

The platform for the ML and GenAI lifecycle.

Packages watched: mlflow (PyPI).

Databricks elsewhere on fru.dev: Acquisitions · Funding · Paydays · Releases · Repos · TechConf

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.