Known Vulnerabilities for MLflow by Na
Listed below are 10 of the newest known vulnerabilities associated with "MLflow" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33866 json | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to mi... | Not Provided | 2026-04-07 | 2026-04-14 |
| CVE-2026-33865 json | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web... | Not Provided | 2026-04-07 | 2026-04-14 |
| CVE-2026-10803 json | A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/dat... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-4137 json | In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates... | Not Provided | 2026-05-18 | 2026-05-19 |
| CVE-2026-4035 json | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway se... | Not Provided | 2026-06-03 | 2026-06-03 |
| CVE-2026-3198 json | MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' ... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-2734 json | In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQ... | Not Provided | 2026-05-21 | 2026-05-21 |
| CVE-2026-2652 json | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the ... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-2651 json | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--s... | Not Provided | 2026-05-25 | 2026-05-27 |
| CVE-2026-2614 json | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and e... | Not Provided | 2026-05-11 | 2026-05-12 |