Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mlflow MEDIUM 6.5
CVE-2026-3198

MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically,…

No fix yet
Fix from $1,600 2026-06-02
Mlflow CRITICAL 9.8
CVE-2026-0545

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…

Mitigation only
Fix from $2,300 2026-04-03
Mlflow HIGH 7.8
CVE-2026-0596

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into…

No fix yet
Fix from $1,950 2026-03-31
Mlflow HIGH 7.1
CVE-2025-15381

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission valida…

No fix yet
Fix from $1,950 2026-03-27
Mlflow HIGH 7.5
CVE-2025-0453EPSS 11%

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries…

No fix yet
Fix from $1,950 2025-03-20
Mlflow MEDIUM 5.3
CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its…

No fix yet
Fix from $1,600 2025-03-20
Mlflow MEDIUM 5.4
CVE-2024-3099

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c…

No fix yet
Fix from $1,600 2024-06-06
Mlflow HIGH 8.8
CVE-2024-37058

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37059

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37060

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37061

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37054

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37055

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37056

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37057

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37052

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…

No fix yet
Fix from $1,950 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37053

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit…

No fix yet
Fix from $1,950 2024-06-04
Mlflow CRITICAL 9.8
CVE-2023-6014

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

No fix yet
Fix from $2,300 2023-11-16
Mlflow CRITICAL 9.8
CVE-2023-6018EPSS 48%

An attacker can overwrite any file on the server hosting MLflow without any authentication.

No fix yet
Fix from $2,300 2023-11-16
Vector Packet Processor HIGH 7.5
CVE-2022-46397

FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C…

Mitigation only
Fix from $1,950 2023-03-28