Where
-Infinity
0

mlflowmlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint

Risk 50
Severity
7.7
First published (updated )

mlflowZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability

Risk 46
Severity
9.8
First published (updated )

MLflow MLflowDenial of Service through Batched Queries in GraphQL in mlflow/mlflow

Risk 43
Severity
7.5
First published (updated )

MLflow MLflowCSRF in mlflow/mlflow

Risk 47
Severity
7.1
First published (updated )

MLflow MLflowWeak Password Requirements in mlflow/mlflow

Risk 39
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MLflow MLflowPath Traversal in mlflow/mlflow

Risk 43
Severity
7.5
First published (updated )

MLflow MLflowUncontrolled Resource Consumption in mlflow/mlflow

Risk 27
Severity
5.3
First published (updated )

pip/mlflowExcessive directory permissions in MLflow leads to local privilege escalation when using spark_udf

Risk 65
Severity
7
First published (updated )

Lfprojects MlflowLocal File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow

Risk 45
Severity
7.5
First published (updated )

Lfprojects MlflowRemote Code Execution due to Full Controlled File Write in mlflow/mlflow

Risk 90
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mlflowDenial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow

Risk 36
Severity
5.4
First published (updated )

pip/mlflowCode Injection, Input Validation

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.…

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0…

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0…

Risk 80
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0…

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.…

Risk 80
Severity
8.8
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.…

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0…

Risk 57
Severity
8.8
EPSS
0.04%
First published (updated )

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0…

Risk 80
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mlflowDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0…

Risk 80
Severity
8.8
First published (updated )

Lfprojects MlflowPath Traversal Bypass in mlflow/mlflow

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

pip/mlflowLocal File Read via Path Traversal in mlflow/mlflow

Risk 45
Severity
7.5
First published (updated )

pip/mlflowPath Traversal Vulnerability in mlflow/mlflow

Risk 45
Severity
7.5
First published (updated )

pip/mlflowPath Traversal via Parameter Smuggling in mlflow/mlflow

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/mlflowPath Traversal Vulnerability in mlflow/mlflow

Risk 45
Severity
7.5
First published (updated )

Lfprojects MlflowLocal File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow

Risk 44
Severity
9.3
EPSS
0.04%
First published (updated )

pip/mlflowPath Traversal Vulnerability in mlflow/mlflow

Risk 62
Severity
8.1
First published (updated )

pip/mlflowPath Traversal: '\..\filename'

Risk 59
Severity
10
EPSS
0.56%
First published (updated )

pip/mlflowUnrestricted Upload of File with Dangerous Type

Risk 57
Severity
8.8
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203