Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3865
  • PyPI/mlflow
MLflow AI Gateway permits SSRF through an unvalidated api_base 10 Sep
  • No fix available
  • Severity - 7.1 (High)
GHSA-gqvg-gmmx-x4hm
  • PyPI/mlflow
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact 01 Sep
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-14384
  • PyPI/mlflow-otel-instrumentor
Malicious code in mlflow-otel-instrumentor (PyPI) 23 Aug
  • No fix available
PYSEC-2026-3687
  • PyPI/mlflow
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 19 Aug
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3686
  • PyPI/mlflow
MLflow: trace API endpoints lack proper authorization validators 19 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-7gwp-5pfp-969j
  • PyPI/mlflow
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 17 Aug
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-h7x2-h6g9-p789
  • PyPI/mlflow
MLflow AI Gateway permits SSRF through an unvalidated api_base 05 Aug
  • No fix available
  • Severity - 7.1 (High)
MAL-2026-10779
  • PyPI/mlflow-ui
Malicious code in mlflow-ui (PyPI) 18 Jul
  • No fix available
PYSEC-2026-2659
  • PyPI/mlflow
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2660
  • PyPI/mlflow
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2655
  • PyPI/mlflow
MLFlow Creates a Temporary File With Insecure Permissions 13 Jul
  • Fix available
  • Severity - 7.0 (High)
PYSEC-2026-2654
  • PyPI/mlflow
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2657
  • PyPI/mlflow
MLFlow allows Tracing + Assessments Access 13 Jul
  • No fix available
  • Severity - 8.1 (High)
PYSEC-2026-2656
  • PyPI/mlflow
Arbitrary file write via tar traversal in mlflow 13 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-2661
  • PyPI/mlflow
MLflow has a command injection in mlflow/sagemaker/__init__.py 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2658
  • PyPI/mlflow
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability 13 Jul
  • Fix available
  • Severity - 8.1 (High)