MLflow has 51 CVEs on record between 2023 and 2026. Cadence is steady at roughly 8 per quarter. The busiest recent month was May 2026 with 5. The median CVSS is 8.1 (high), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-502 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 8 prev 10
Weakness classes
Products
- MLflow 51
Worst active — by depth score
CVE-2025-11201High· 8.1MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability75CVE-2026-2033High· 8.1MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability70CVE-2025-11200High· 8.1MLflow Weak Password Requirements Authentication Bypass Vulnerability70CVE-2026-2635High· 7.3MLflow Use of Default Password Authentication Bypass Vulnerability65CVE-2024-37054High· 8.8MLFlow unsafe deserialization61
MLflow vulnerabilities
CVEs affecting MLflow, newest first. Open any entry for full detail, references, and exploit status.
51 CVEsRSS
CVE-2025-0453Medium· 5.9MLflow Uncontrolled Resource Consumption vulnerability
MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-3099Medium· 5.4Undefined Behavior in mlflow
Undefined Behavior in mlflow
CVE-2024-37055High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37061High· 8.8MLFlow improper input validation
MLFlow improper input validation
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37054High· 8.8PoCMLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37058High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37060High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37056High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37052High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37053High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-1594High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1558High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-1593High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1560High· 8.1mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2023-6976High· 8.8MLflow Path Traversal Vulnerability
MLflow Path Traversal Vulnerability
CVE-2023-6977High· 7.5PoCMLflow Local File Disclosure Vulnerability
MLflow Local File Disclosure Vulnerability
CVE-2023-6940High· 8.8mlflow Command Injection vulnerability
mlflow Command Injection vulnerability
CVE-2023-43472High· 7.5PoCInformation exposure in MLflow
Information exposure in MLflow