Vulnerabilities in MLflow
78 resultsVexday analysis
MLflow apresenta 14 vulnerabilidades catalogadas, predominantemente ligadas a desserialização insegura (CWE-502), mas sem nenhuma exploração ativa registrada ou crítica máxima identificada. O risco atual é contido pela ausência de ataques em campanha, embora a natureza das falhas (desserialização) represente vetor potencial em ambientes expostos; nenhuma vulnerabilidade foi publicada nos últimos 90 dias.
CVE-2024-3099MEDIUMDenial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflowEPSS 0.4%CVE-2026-96804HIGHCVE-2026-96804EPSS 0.4%CVE-2026-2611CRITICALImproper Origin Validation in mlflow/mlflowEPSS 0.4%CVE-2026-69146MEDIUMMLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-authEPSS 0.4%CVE-2026-96775HIGHMLflow dspy bypasses pickle deserialization controlEPSS 0.4%CVE-2026-33866MEDIUMAuthorization Bypass in MLflow AJAX EndpointEPSS 0.4%CVE-2026-69148HIGHMLflow: CreateModelVersion source validation does not check READ permission on referenced run_idEPSS 0.4%CVE-2025-1474LOWWeak Password Requirements in mlflow/mlflowEPSS 0.4%CVE-2026-3198MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.4%CVE-2024-4263MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.3%CVE-2025-15381HIGHUnauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflowEPSS 0.3%CVE-2026-33865MEDIUMStored XSS via unsafe YAML parsing in MLflowEPSS 0.3%CVE-2026-71211HIGHmlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy EndpointEPSS 0.3%CVE-2026-2393HIGHServer-Side Request Forgery (SSRF) in mlflow/mlflowEPSS 0.3%CVE-2025-10279HIGHPrivilege Escalation in mlflow/mlflowEPSS 0.2%CVE-2025-1473MEDIUMCSRF in mlflow/mlflowEPSS 0.2%CVE-2025-14279HIGHDNS Rebinding Vulnerability in mlflow/mlflowEPSS 0.2%CVE-2026-4137HIGHIncomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflowEPSS 0.2%