mlflow has 49 CVEs on record between 2023 and 2026. Disclosures have slowed: 6 in the last 90 days after 11 in the 90 before. The busiest recent month was May 2026 with 5. The median CVSS is 8.1 (high), with 3 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 6 prev 11
Weakness classes
Products
- mlflow 49
Worst active — by depth score
CVE-2025-11201High· 8.1MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability75CVE-2026-2033High· 8.1MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability70CVE-2025-11200High· 8.1MLflow Weak Password Requirements Authentication Bypass Vulnerability70CVE-2026-2635High· 7.3MLflow Use of Default Password Authentication Bypass Vulnerability65CVE-2026-2652High· 8.6MLflow: unauthenticated access to certain FastAPI routes63
mlflow vulnerabilities
CVEs affecting mlflow, newest first. Open any entry for full detail, references, and exploit status.
49 CVEsRSS
CVE-2026-79721High· 8.6Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
GHSA-gqvg-gmmx-x4hmHigh· 8.8MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
CVE-2026-69146Medium· 6.5MLflow is an open source AI engineering platform for agents, large language models, and machine learning models
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…
CVE-2026-69148High· 7.1MLflow is an open source AI engineering platform for agents, large language models, and machine learning models
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…
CVE-2026-71211High· 7.1PoCMLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…
CVE-2026-8147High· 8.1MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
CVE-2026-10803Low· 3.6MLflow: Deterministic sampling in dataset digest enables predictable collisions
MLflow: Deterministic sampling in dataset digest enables predictable collisions
CVE-2026-4035Critical· 9.1MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
CVE-2026-3198Medium· 6.5MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
CVE-2026-2651Critical· 9.0MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
CVE-2026-2734Medium· 6.5MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-4137High· 7.0MLFlow Creates a Temporary File With Insecure Permissions
MLFlow Creates a Temporary File With Insecure Permissions
CVE-2026-2652High· 8.6PoCMLflow: unauthenticated access to certain FastAPI routes
MLflow: unauthenticated access to certain FastAPI routes
CVE-2026-2393High· 7.1MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-33866Medium· 4.3MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
CVE-2025-15036Critical· 9.6MLFlow path traversal vulnerability
MLFlow path traversal vulnerability
CVE-2025-15381High· 8.1MLFlow allows Tracing + Assessments Access
MLFlow allows Tracing + Assessments Access
CVE-2025-15031High· 8.1Arbitrary file write via tar traversal in mlflow
Arbitrary file write via tar traversal in mlflow
CVE-2025-14287High· 7.5MLflow has a command injection in mlflow/sagemaker/__init__.py
MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2026-2033High· 8.10dayMLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
CVE-2026-2635High· 7.30day⚖ disputedMLflow Use of Default Password Authentication Bypass Vulnerability
MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…
CVE-2025-10279High· 7.0mlflow Creates of Temporary File in Directory with Insecure Permissions
mlflow Creates of Temporary File in Directory with Insecure Permissions
CVE-2025-14279High· 8.1MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
CVE-2025-11200High· 8.10dayMLflow Weak Password Requirements Authentication Bypass Vulnerability
MLflow Weak Password Requirements Authentication Bypass Vulnerability
CVE-2025-11201High· 8.10dayMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CVE-2024-6838Medium· 5.3MLflow Uncontrolled Resource Consumption vulnerability
MLflow Uncontrolled Resource Consumption vulnerability
CVE-2025-1473Medium· 5.4MLflow Cross-Site Request Forgery (CSRF) vulnerability
MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2024-8859High· 7.5PoCMLflow has a Local File Read/Path Traversal in dbfs
MLflow has a Local File Read/Path Traversal in dbfs
CVE-2025-0453Medium· 5.9MLflow Uncontrolled Resource Consumption vulnerability
MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-3099Medium· 5.4Undefined Behavior in mlflow
Undefined Behavior in mlflow