pkg:PyPI/mlflow
96 total CVEsCRITICAL28HIGH50MEDIUM14LOW4
✅ Check your installed version
All known vulnerabilities
- from 0, < 3.8.1
- from 0, < 2.9.0
- from 0, < 400c226953b4568f4361bc0a0c223511652c2b9d, < 400c226953b4568f4361bc0a0c223511652c2b9d | from 0, < 2.9.0
- from 0, < 2.9.2
- from 0, < 1da75dfcecd4d169e34809ade55748384e8af6c1 | from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.8.1
- from 0, < 6dde93758d42455cb90ef324407919ed67668b9b, < 6dde93758d42455cb90ef324407919ed67668b9b | from 0, < 2.5.0
- from 0, < 2.5.0
- from 0, < f73147496e05c09a8b83d95fb4f1bf86696c6342 | from 0, < 2.3.1
- from 0, < 2.3.1
- from 0, < 3.8.0rc0
- from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.3.0
- from 0, < fae77a525dd908c56d6204a4cef1c1c75b4e9857 | from 0, < 2.3.1
- from 0, < 7162a50c654792c21f3e4a160eb1a0e6a34f6e6e | from 0, < 2.2.1
- from 0, < 2.2.1
- from 0, < 3.9.0
- from 0, < 3.9.0rc0
- CRITICAL9.6CVE-2024-27132Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.from 0, < 2.10.0
- CRITICAL9.6CVE-2024-27133Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.from 0, < 2.10.0
- CRITICAL9.6CVE-2024-27133Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.from 0, < 2.10.0
- CRITICAL9.6CVE-2024-27132Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.from 0, < 2.10.0
- from 0, < 438a450714a3ca06285eeea34bdc6cf79d7f6cbc, < 438a450714a3ca06285eeea34bdc6cf79d7f6cbc | from 0, < 2.10.0
- from 0, < 2.10.0
- CRITICAL9.1CVE-2026-0545mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorizationfrom 0, <= 3.10.1
- CRITICAL9.1CVE-2023-6014MLflow authentication requirement bypass can allow a user to arbitrarily create an accountfrom 0, < 2.8.0
- >= 2.0.0rc0, <= 2.14.1
- >= 1.27.0, <= 2.14.1
- >= 2.5.0, <= 2.14.1
- >= 1.11.0, <= 2.13.1
- >= 0.5.0, <= 3.4.0
- >= 1.23.0, <= 2.14.1
- >= 1.24.0, <= 2.14.1
- >= 0.9.0, <= 2.14.1
- >= 1.1.0, <= 2.14.1
- >= 1.1.0, <= 2.14.1
- from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 1c6309f884798fbf56017a3cc808016869ee8de4, < 1c6309f884798fbf56017a3cc808016869ee8de4 | from 0, < 2.9.2
- from 0, < 2.9.2
- HIGH8.8CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowfrom 0, < 2.9.2
- HIGH8.8CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowfrom 0, < 432b8ccf27fd3a76df4ba79bb1bec62118a85625 | from 0, < 2.9.2
- from 0, < 2.6.0
- from 0, < 6dde93758d42455cb90ef324407919ed67668b9b | from 0, < 2.6.0
- from 0, < 3.11.0
- from 0, < 61984e6843d2e59235d82a580c529920cd8f3711 | from 0, < 1.23.1
- from 0, < 1.23.1
- from 0, <= 3.8.1
- from 0, < 3.9.0rc0
- HIGH8.1CVE-2026-2033MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerabilityfrom 0, < 3.8.0rc0
- from 0, < 3.5.0
- from 0, < 2.22.0rc0
- HIGH8.1CVE-2025-11201MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability>= 3.0.0rc0, < 3.0.0
- from 0, <= 2.9.2
- from 0, < 3.10.0
- from 0, < 3.8.0rc0
- from 0, < 2.17.0rc0
- from 0, < 2.11.3
- from 0, < 96f0b573a73d8eedd6735a2ce26e08859527be07, < 96f0b573a73d8eedd6735a2ce26e08859527be07 | from 0, < 2.11.3
- >= 2.9.2, < 2.12.1
- from 0, < f8d51e21523238280ebcfdb378612afd7844eca8, < f8d51e21523238280ebcfdb378612afd7844eca8 | from 0, < 2.12.1
- from 0, <= 2.9.2
- from 0, <= 2.9.2
- from 0, < 2.12.1
- from 0, < 2.12.1
- from 0, < 1da75dfcecd4d169e34809ade55748384e8af6c1 | from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.9.2
- from 0, < 2.9.0
- from 0, < 2.0.1
- from 0, < 2.0.0rc0
- from 0, < 3.9.0
- from 0, < 3.11.0
- from 0, < 3.4.0rc0
- HIGH7.0CVE-2024-27134Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udffrom 0, < 2.16.0
- HIGH7.0CVE-2024-27134Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udffrom 0, < 2.16.0
- from 0, < 28ff3f94994941e038f2172c6484b65dc4db6ca1 | from 0, < 2.9.1
- from 0, < 2.9.0
- from 0, <= 2.17.2
- from 0, < 39a419b4ec8fd11b59b3e50ab397042a490f2324 | from 0, < 3.1.0
- >= 3.0.0rc0, < 3.1.0
- from 0, < 3.11.1
- from 0, < 3.11.0rc0
- >= 2.17.0, < 2.20.3
- from 0, < 2.11.3
- from 0, < 2.10.1
- from 0, < b43e0e3de5b500554e13dc032ba2083b2d6c94b8 | from 0, < 2.10.1
- from 0, <= 2.13.2
- from 0, <= 3.10.1
- from 0, < 3.11.0rc0
- from 0, < 149c9e18aa219bc47e86b432e130e467a36f4a17 | from 0, < 2.19.0
- from 0, < 2.19.0
- from 0, < 63ef72aa4334a6473ce7f889573c92fcae0b3c0d | from 0, < 2.2.2
- from 0, < 2.2.1