mlflow vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-11201Highmlflow: MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution VulnerabilityCVE-2025-52967Mediummlflow: MLFlow SSRF via gateway_proxy_handlerCVE-2025-1473Mediummlflow: MLflow Cross-Site Request Forgery (CSRF) vulnerabilityCVE-2025-1474Lowmlflow: MLflow has Weak Password RequirementsCVE-2025-0453Mediummlflow: MLflow Uncontrolled Resource Consumption vulnerabilityCVE-2024-8859Highmlflow: MLflow has a Local File Read/Path Traversal in dbfsCVE-2024-6838Mediummlflow: MLflow Uncontrolled Resource Consumption vulnerabilityCVE-2024-27134Highmlflow: MLflow's excessive directory permissions allow local privilege escalationCVE-2024-2928Highmlflow: Local File Inclusion in mlflowCVE-2024-3099Mediummlflow: Undefined Behavior in mlflowCVE-2024-0520Criticalmlflow: Remote code execution in mlflowCVE-2024-37060Highmlflow: MLFlow unsafe deserializationCVE-2024-37061Highmlflow: MLFlow improper input validationCVE-2024-37058Highmlflow: MLFlow unsafe deserializationCVE-2024-37059Highmlflow: MLFlow unsafe deserializationCVE-2024-37057Highmlflow: MLFlow unsafe deserializationCVE-2024-37054Highmlflow: MLFlow unsafe deserializationCVE-2024-37055Highmlflow: MLFlow unsafe deserializationCVE-2024-37052Highmlflow: MLFlow unsafe deserializationCVE-2024-37056Highmlflow: MLFlow unsafe deserializationCVE-2024-37053Highmlflow: MLFlow unsafe deserializationCVE-2024-3848Highmlflow: MLflow has a Local File Read/Path Traversal bypassCVE-2024-4263Mediummlflow: MLflow allows low privilege users to delete any artifactCVE-2024-3573Criticalmlflow: mlflow vulnerable to Path TraversalCVE-2024-1560Highmlflow: mlflow vulnerable to Path Traversal

Stop the waste.
Protect your environment with Kodem.