Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-3198 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically,… Mlflow No fix yet Fix from $1,6002026-06-02 CRITICAL 9.8 CVE-2026-0545 In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a… Mlflow Mitigation only Fix from $2,3002026-04-03 HIGH 7.8 CVE-2026-0596 A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into… Mlflow No fix yet Fix from $1,9502026-03-31 HIGH 7.1 CVE-2025-15381 In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission valida… Mlflow No fix yet Fix from $1,9502026-03-27 HIGH 7.5 CVE-2025-0453EPSS 11% In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries… Mlflow No fix yet Fix from $1,9502025-03-20 MEDIUM 5.3 CVE-2024-6838 In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its… Mlflow No fix yet Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-3099 A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw c… Mlflow No fix yet Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-37058 Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langch… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37059 Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorc… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37060 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37061 Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37054 Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37055 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdar… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37056 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded Light… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37057 Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Ten… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37052 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit… Mlflow No fix yet Fix from $1,9502024-06-04 HIGH 8.8 CVE-2024-37053 Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit… Mlflow No fix yet Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2023-6014 An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. Mlflow No fix yet Fix from $2,3002023-11-16 CRITICAL 9.8 CVE-2023-6018EPSS 48% An attacker can overwrite any file on the server hosting MLflow without any authentication. Mlflow No fix yet Fix from $2,3002023-11-16 HIGH 7.5 CVE-2022-46397 FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with C… Vector Packet Processor Mitigation only Fix from $1,9502023-03-28