Vulnerabilities in MLflow
78 resultsVexday analysis
MLflow apresenta 14 vulnerabilidades catalogadas, predominantemente ligadas a desserialização insegura (CWE-502), mas sem nenhuma exploração ativa registrada ou crítica máxima identificada. O risco atual é contido pela ausência de ataques em campanha, embora a natureza das falhas (desserialização) represente vetor potencial em ambientes expostos; nenhuma vulnerabilidade foi publicada nos últimos 90 dias.
CVE-2024-37060HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously craftEPSS 0.8%CVE-2024-3573CRITICALLocal File Inclusion (LFI) via Scheme Confusion in mlflow/mlflowEPSS 0.7%CVE-2024-1594HIGHLocal File Read via Path Traversal in mlflow/mlflowEPSS 0.7%CVE-2024-37054HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploadEPSS 0.7%CVE-2024-1593HIGHPath Traversal via Parameter Smuggling in mlflow/mlflowEPSS 0.7%CVE-2024-37052HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploadEPSS 0.7%CVE-2026-4035HIGHEnvironment Variable Resolution Vulnerability in mlflow/mlflowEPSS 0.7%CVE-2024-6838MEDIUMUncontrolled Resource Consumption in mlflow/mlflowEPSS 0.7%CVE-2024-37055HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-37059HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2024-37053HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2024-37057HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uplEPSS 0.6%CVE-2024-37056HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-37058HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploadEPSS 0.6%CVE-2023-1176MEDIUMAbsolute Path Traversal in mlflow/mlflowEPSS 0.6%CVE-2025-15036CRITICALPath Traversal Vulnerability in mlflow/mlflowEPSS 0.6%CVE-2026-8147HIGHAuthorization Bypass in mlflow/mlflowEPSS 0.5%CVE-2026-2651CRITICALMissing Authorization Validation in mlflow/mlflowEPSS 0.5%CVE-2026-2734MEDIUMAuthorization Bypass in SearchModelVersions in mlflow/mlflowEPSS 0.5%CVE-2026-79721HIGHCode execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact toEPSS 0.5%