mlrun vulnerabilities
CVEs whose affected-version data names the mlrun package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92568Medium· 5.4PoCMLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses
MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update …
▾ Twilightmlrun · mlrunEPSS 0.29%via NVD
CVE-2026-10766Low· 3.6mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
▾ Sunlitmlrun · mlrunEPSS 0.07%via OSV