MLflow security advisories
82 advisories · 24 critical or high in 12 months · latest Sep 1
60 of 82 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifact GHSA-gqvg-gmmx-x4hmHigh8.8fixed in 3.15.0 | High8.8 | 3.15.0 |
| Aug 17 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CVE-2026-64849Critical9.3fixed in 3.15.0 | Critical9.3 | 3.15.0 |
| Aug 5 | MLflow AI Gateway permits SSRF through an unvalidated api_base CVE-2026-71211High7.1no fix yet | High7.1 | No fix yet |
| Jul 2 | MLflow: trace API endpoints lack proper authorization validators CVE-2026-8147High8.1fixed in 3.13.0rc0 | High8.1 | 3.13.0rc0 |
| Jun 4 | MLflow: Deterministic sampling in dataset digest enables predictable collisions CVE-2026-10803Low3.6fixed in 3.10.1 | Low3.6 | 3.10.1 |
| Jun 3 | MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration CVE-2026-4035Critical9.1fixed in 3.11.0 | Critical9.1 | 3.11.0 |
| Jun 2 | MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions CVE-2026-3198Medium6.5fixed in 3.11.0rc0 | Medium6.5 | 3.11.0rc0 |
| May 26 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled CVE-2026-2651Critical9.0fixed in 3.11.0rc1 | Critical9.0 | 3.11.0rc1 |
| May 21 | MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks CVE-2026-2734Medium6.5fixed in 3.10.0 | Medium6.5 | 3.10.0 |
| May 19 | MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution CVE-2026-2611Critical9.6fixed in 3.10.0 | Critical9.6 | 3.10.0 |
| May 18 | MLFlow Creates a Temporary File With Insecure Permissions CVE-2026-4137High7.0fixed in 3.11.0 | High7.0 | 3.11.0 |
| May 15 | MLflow: unauthenticated access to certain FastAPI routes CVE-2026-2652High8.6fixed in 3.11.0 | High8.6 | 3.11.0 |
| May 11 | MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem CVE-2026-2614High7.5fixed in 3.10.0 | High7.5 | 3.10.0 |
| May 11 | MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability CVE-2026-2393High7.1fixed in 3.9.0 | High7.1 | 3.9.0 |
| Apr 7 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint CVE-2026-33866Medium4.3fixed in 3.11.0rc0 | Medium4.3 | 3.11.0rc0 |
| Apr 7 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface CVE-2026-33865Medium5.4fixed in 3.11.1 | Medium5.4 | 3.11.1 |
| Apr 3 | mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization CVE-2026-0545Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 31 | Mlflow: Command Injection when serving models with enable_mlserver=True CVE-2026-0596Critical9.6fixed in 3.9.0 | Critical9.6 | 3.9.0 |
| Mar 30 | MLflow Command Injection vulnerability CVE-2025-15379Critical10.0fixed in 3.8.1 | Critical10.0 | 3.8.1 |
| Mar 30 | MLFlow path traversal vulnerability CVE-2025-15036Critical9.6fixed in 3.9.0rc0 | Critical9.6 | 3.9.0rc0 |
| Mar 27 | MLFlow allows Tracing + Assessments Access CVE-2025-15381High8.1no fix yet | High8.1 | No fix yet |
| Mar 19 | Arbitrary file write via tar traversal in mlflow CVE-2025-15031High8.1fixed in 3.9.0rc0 | High8.1 | 3.9.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py CVE-2025-14287High7.5fixed in 3.8.0rc0 | High7.5 | 3.8.0rc0 |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability CVE-2026-2635Critical9.8fixed in 3.8.0rc0 | Critical9.8 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability CVE-2026-2033High8.1fixed in 3.8.0rc0 | High8.1 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions CVE-2025-10279High7.0fixed in 3.4.0rc0 | High7.0 | 3.4.0rc0 |
| Jan 12 | MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation CVE-2025-14279High8.1fixed in 3.5.0 | High8.1 | 3.5.0 |
| Oct 292025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability CVE-2025-11201High8.1fixed in 2.22.4, 3.0.0 | High8.1 | 2.22.4, 3.0.0 |
| Oct 292025 | MLflow Weak Password Requirements Authentication Bypass Vulnerability CVE-2025-11200High8.1fixed in 2.22.0rc0 | High8.1 | 2.22.0rc0 |
| Jun 232025 | MLFlow SSRF via gateway_proxy_handler CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0 | Medium5.8 | 2.22.2, 3.1.0 |
| Mar 202025 | MLflow has Weak Password Requirements CVE-2025-1474Low3.8fixed in 2.19.0 | Low3.8 | 2.19.0 |
| Mar 202025 | MLflow Cross-Site Request Forgery (CSRF) vulnerability CVE-2025-1473Medium5.4fixed in 2.20.3 | Medium5.4 | 2.20.3 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2025-0453Medium5.9no fix yet | Medium5.9 | No fix yet |
| Mar 202025 | MLflow has a Local File Read/Path Traversal in dbfs CVE-2024-8859High7.5fixed in 2.17.0rc0 | High7.5 | 2.17.0rc0 |
| Mar 202025 | MLflow Uncontrolled Resource Consumption vulnerability CVE-2024-6838Medium5.3no fix yet | Medium5.3 | No fix yet |
| Nov 252024 | MLflow's excessive directory permissions allow local privilege escalation CVE-2024-27134High7.0fixed in 2.16.0 | High7.0 | 2.16.0 |
| Jun 62024 | Undefined Behavior in mlflow CVE-2024-3099Medium5.4fixed in 2.11.3 | Medium5.4 | 2.11.3 |
| Jun 62024 | Local File Inclusion in mlflow CVE-2024-2928High7.5fixed in 2.11.3 | High7.5 | 2.11.3 |
| Jun 62024 | Remote code execution in mlflow CVE-2024-0520Critical10.0fixed in 2.9.0 | Critical10.0 | 2.9.0 |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37060High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37058High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37057High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow improper input validation CVE-2024-37061High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37059High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37053High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37052High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37056High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37054High8.8no fix yet | High8.8 | No fix yet |
| Jun 42024 | MLFlow unsafe deserialization CVE-2024-37055High8.8no fix yet | High8.8 | No fix yet |
| May 162024 | MLflow allows low privilege users to delete any artifact CVE-2024-4263Medium5.4fixed in 2.10.1 | Medium5.4 | 2.10.1 |
| May 162024 | MLflow has a Local File Read/Path Traversal bypass CVE-2024-3848High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-3573Critical9.3fixed in 2.10.0 | Critical9.3 | 2.10.0 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1560High8.1no fix yet | High8.1 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1593High7.5no fix yet | High7.5 | No fix yet |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1558High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Apr 162024 | mlflow vulnerable to Path Traversal CVE-2024-1594High7.5no fix yet | High7.5 | No fix yet |
| Apr 162024 | mlflow Path Traversal vulnerability CVE-2024-1483High7.5fixed in 2.12.1 | High7.5 | 2.12.1 |
| Feb 242024 | MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution CVE-2024-27133Critical9.6fixed in 2.10.0 | Critical9.6 | 2.10.0 |
| Feb 242024 | Cross-site Scripting in MLFlow CVE-2024-27132Critical9.6fixed in 2.10.0 | Critical9.6 | 2.10.0 |
| Dec 202023 | MLflow Server-Side Request Forgery (SSRF) CVE-2023-6974Critical9.8fixed in 2.9.2 | Critical9.8 | 2.9.2 |