Loading...
Skip to main content
PyPI (Python)

mlflow Security Analysis

mlflow has 14 known security vulnerabilities in PyPI (Python). Upgrade to version 3.15.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

14 Vulnerabilities

Actively Exploited

CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.

Recommended safe version: 3.15.0

Upgrading to 3.15.0 or later resolves all 14 known vulnerabilities in mlflow. Run: pip install "mlflow>=3.15.0"

Is mlflow in your project?

Check if you're affected and upgrade to 3.15.0 to stay secure.

14
Total
0
Critical
0
High
0
Medium
0
Low

Active Exploitation Warning

One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.

Vulnerabilities

14 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+178 more)3.15.0
CVE-2023-6015
MLflow allowed arbitrary files to be PUT onto the server
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+78 more)2.8.1
CVE-2023-6018
Remote Code Execution due to Full Controled File Write in mlflow
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+81 more)2.9.2
CVE-2026-2635
MLflow Use of Default Password Authentication Bypass Vulnerability
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+161 more)3.8.0rc0
CVE-2023-6974
MLflow Server-Side Request Forgery (SSRF)
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+81 more)2.9.2
CVE-2026-2635
MLflow Use of Default Password Authentication Bypass Vulnerability
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+160 more)3.8.0rc0
CVE-2026-2611
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CRITICAL
3.10.0rc0, 3.9.03.10.0
CVE-2026-0596
Mlflow: Command Injection when serving models with enable_mlserver=True
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+165 more)3.9.0
CVE-2026-2611
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CRITICAL
3.10.0rc0, 3.9.03.10.0
CVE-2026-0596
Mlflow: Command Injection when serving models with enable_mlserver=True
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+165 more)3.9.0
CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+178 more)3.15.0
CVE-2026-0545
mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+169 more)No fix available
CVE-2023-6014
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+77 more)2.8.0
CVE-2026-4035
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
CRITICAL
0.0.1, 0.1.0, 0.2.0, 0.2.1 (+171 more)3.11.0

About This Data

Vulnerability data for mlflow is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related PyPI (Python) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of mlflow.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed