Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mlflow — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in mlflow, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known Common Weakness Enumerations (CWE) and associated vulnerabilities affecting MLflow, an open-source platform for the machine learning lifecycle. The content collected here spans a broad historical timeline, documenting security issues from early releases through to recent updates, ensuring a comprehensive view of the product's security evolution. Users can track vendor advisories and release notes to stay informed about critical patches, gain a deeper understanding of specific weakness classes such as injection flaws or insecure deserialization within the MLflow codebase, and look up the complete vulnerability history of the product to assess risk exposure over time. By consolidating this data, the page serves as a centralized reference for security researchers, DevOps engineers, and data scientists who need to evaluate the integrity of their machine learning pipelines. The information is structured to facilitate quick identification of affected versions and recommended mitigation strategies, allowing teams to prioritize remediation efforts effectively. This resource does not provide real-time monitoring but offers a static, detailed record of past security events. It is designed to support audit processes, compliance reporting, and internal security reviews by providing clear context on how various weaknesses have manifested in MLflow. Readers can use this data to correlate specific versions with known defects, ensuring that deployment environments are hardened against previously exploited threats. The aggregation focuses on factual reporting of vulnerabilities without editorial commentary, ensuring objectivity and accuracy for professional security assessments.

Vendor: MLflow

CVE IDTitleCVSSSeverityPublished
CVE-2026-71211 mlflow: Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint CWE-918 7.1 High2026-08-05
CVE-2026-13484 MLflow Experiment-scoped Label Schema CRUD API authorization CWE-862 5.0 Medium2026-06-28
CVE-2026-10803 MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash CWE-328 3.6 Low2026-06-04
CVE-2026-33866 Authorization Bypass in MLflow AJAX Endpoint CWE-862 4.3AIMediumAI2026-04-07
CVE-2026-33865 Stored XSS via unsafe YAML parsing in MLflow CWE-79 5.4AIMediumAI2026-04-07
CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability CWE-1393 9.8AICriticalAI2026-02-20
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8AICriticalAI2026-02-20
CVE-2025-11200 MLflow Weak Password Requirements Authentication Bypass Vulnerability CWE-521 9.8AICriticalAI2025-10-29
CVE-2025-11201 MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8AICriticalAI2025-10-29
CVE-2025-52967 MLflow 代码问题漏洞 CWE-918 5.8 Medium2025-06-23
CVE-2024-37061 MLflow 安全漏洞 CWE-94 8.8 High2024-06-04
CVE-2024-37060 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37059 Mlflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37058 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37057 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37056 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37055 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37054 MLflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37053 Mlflow 安全漏洞 CWE-502 8.8 High2024-06-04
CVE-2024-37052 Mlflow 安全漏洞 CWE-502 8.8 High2024-06-04

All 20 known CVE vulnerabilities affecting mlflow with full Chinese analysis, references, and POCs where available.