CVEs we hold for Mlflow/mlflow
Records whose assigning authority named Mlflow/mlflow as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflowmlflow/mlflow CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2026-3198Improper Access Control in mlflow/mlflowmlflow/mlflow CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflowmlflow/mlflow CVE-2026-2651Missing Authorization Validation in mlflow/mlflowmlflow/mlflow CVE-2026-2614Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflowmlflow/mlflow CVE-2026-2611Improper Origin Validation in mlflow/mlflowmlflow/mlflow CVE-2026-2393Server-Side Request Forgery (SSRF) in mlflow/mlflowmlflow/mlflow CVE-2026-0545Missing Authentication for Critical Function in mlflow/mlflowmlflow/mlflow CVE-2025-15381Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflowmlflow/mlflow CVE-2025-15036Path Traversal Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2025-15031Path Traversal Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2025-1474Weak Password Requirements in mlflow/mlflowmlflow/mlflow CVE-2025-14279DNS Rebinding Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2025-0453Denial of Service through Batched Queries in GraphQL in mlflow/mlflowmlflow/mlflow CVE-2024-6838Uncontrolled Resource Consumption in mlflow/mlflowmlflow/mlflow CVE-2024-4263Improper Access Control in mlflow/mlflowmlflow/mlflow CVE-2024-3573Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflowmlflow/mlflow CVE-2024-3099Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflowmlflow/mlflow CVE-2024-2928Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflowmlflow/mlflow CVE-2024-1594Local File Read via Path Traversal in mlflow/mlflowmlflow/mlflow CVE-2024-1593Path Traversal via Parameter Smuggling in mlflow/mlflowmlflow/mlflow CVE-2024-1560Path Traversal Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2024-1558Path Traversal Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2024-1483Path Traversal Vulnerability in mlflow/mlflowmlflow/mlflow CVE-2024-0520Remote Code Execution due to Full Controlled File Write in mlflow/mlflowmlflow/mlflow CVE-2023-6976Unrestricted Upload of File with Dangerous Typemlflow/mlflow CVE-2023-6909Path Traversal: '\..\filename' in mlflow/mlflowmlflow/mlflow CVE-2023-6831Path Traversal: '\..\filename' in mlflow/mlflowmlflow/mlflow CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowmlflow/mlflow CVE-2023-6568Reflected XSS via Content-Type Header in mlflow/mlflowmlflow/mlflow CVE-2023-3765Absolute Path Traversal in mlflow/mlflowmlflow/mlflow CVE-2023-2780Path Traversal: '\..\filename' in mlflow/mlflowmlflow/mlflow CVE-2023-2356Relative Path Traversal in mlflow/mlflowmlflow/mlflow CVE-2023-1177Path Traversal: '\..\filename' in mlflow/mlflowmlflow/mlflow CVE-2023-1176Absolute Path Traversal in mlflow/mlflowmlflow/mlflow CVE-2022-0736Insecure Temporary File in mlflow/mlflowmlflow/mlflow 55 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.