- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 55 analyzed records
As of 09/11/2026, within CyStack's analyzed data, mlflow/mlflow has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of mlflow/mlflow and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-8147Authorization Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published07/02/2026 | SeverityHigh |
CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published06/03/2026 | SeverityCritical |
CVE-2026-3198Improper Access Control in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/02/2026 | SeverityMedium |
CVE-2026-2651Missing Authorization Validation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/25/2026 | SeverityCritical |
CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/21/2026 | SeverityMedium |
CVE-2026-2611Improper Origin Validation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/19/2026 | SeverityCritical |
CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/18/2026 | SeverityHigh |
CVE-2026-2652Authentication Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/15/2026 | SeverityHigh |
CVE-2026-2614Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/11/2026 | SeverityHigh |
CVE-2026-2393Server-Side Request Forgery (SSRF) in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/11/2026 | SeverityHigh |
CVE-2026-0545Missing Authentication for Critical Function in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/03/2026 | SeverityCritical |
CVE-2026-0596Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/31/2026 | SeverityCritical |
CVE-2025-15379Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/30/2026 | SeverityCritical |
CVE-2025-15036Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/30/2026 | SeverityCritical |
CVE-2025-15381Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow | Exploitation statusNot known exploited | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2025-15031Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/18/2026 | SeverityHigh |
CVE-2025-14287Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2026 | SeverityHigh |
CVE-2025-10279Privilege Escalation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published02/02/2026 | SeverityHigh |
CVE-2025-14279DNS Rebinding Vulnerability in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Published01/12/2026 | SeverityHigh |
CVE-2025-0453Denial of Service through Batched Queries in GraphQL in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2025-1474Weak Password Requirements in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityLow |
CVE-2025-1473CSRF in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityMedium |
CVE-2024-8859Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityHigh |
CVE-2024-6838Uncontrolled Resource Consumption in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-2928Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Published06/06/2024 | SeverityHigh |
CVE-2024-0520Remote Code Execution due to Full Controlled File Write in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published06/06/2024 | SeverityCritical |
CVE-2024-3099Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/06/2024 | SeverityMedium |
CVE-2024-4263Improper Access Control in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Published05/16/2024 | SeverityMedium |
CVE-2024-3848Path Traversal Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/16/2024 | SeverityHigh |
CVE-2024-3573Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published04/16/2024 | SeverityCritical |
CVE-2024-1558Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/16/2024 | SeverityHigh |
CVE-2024-1594Local File Read via Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/16/2024 | SeverityHigh |
CVE-2024-1593Path Traversal via Parameter Smuggling in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/16/2024 | SeverityHigh |
CVE-2024-1483Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/16/2024 | SeverityHigh |
CVE-2024-1560Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/16/2024 | SeverityHigh |
CVE-2023-6977Path Traversal: '\..\filename' | Exploitation statusNot confirmed | FixYes | Published12/20/2023 | SeverityCritical |
CVE-2023-6976Unrestricted Upload of File with Dangerous Type | Exploitation statusNot confirmed | FixYes | Published12/20/2023 | SeverityHigh |
CVE-2023-6975Path Traversal: '\..\filename' | Exploitation statusNot confirmed | FixYes | Published12/20/2023 | SeverityCritical |
CVE-2023-6974Server-Side Request Forgery (SSRF) | Exploitation statusNot confirmed | FixYes | Published12/20/2023 | SeverityHigh |
CVE-2023-6940Command Injection | Exploitation statusNot known exploited | FixYes | Published12/19/2023 | SeverityCritical |
CVE-2023-6909Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Published12/18/2023 | SeverityHigh |
CVE-2023-6831Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Published12/15/2023 | SeverityHigh |
CVE-2023-6753Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published12/13/2023 | SeverityCritical |
CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published12/12/2023 | SeverityCritical |
CVE-2023-6568Reflected XSS via Content-Type Header in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Published12/07/2023 | SeverityMedium |
CVE-2023-6014MLflow Authentication Bypass | Exploitation statusPublic exploit | FixNot confirmed | Published11/16/2023 | SeverityCritical |
CVE-2023-6015MLflow Arbitrary File Upload | Exploitation statusNot confirmed | FixNot confirmed | Published11/16/2023 | SeverityCritical |
CVE-2023-6018MLflow Arbitrary File Write | Exploitation statusNot confirmed | FixNot confirmed | Published11/16/2023 | SeverityCritical |
CVE-2023-4033OS Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published08/01/2023 | SeverityHigh |
CVE-2023-3765Absolute Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published07/19/2023 | SeverityCritical |
CVE-2023-2780Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published05/17/2023 | SeverityCritical |
CVE-2023-2356Relative Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published04/28/2023 | SeverityCritical |
CVE-2023-1177Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/24/2023 | SeverityCritical |
CVE-2023-1176Absolute Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Published03/24/2023 | SeverityMedium |
CVE-2022-0736Insecure Temporary File in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Published02/23/2022 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan