Vulnerabilities in Mlflow
72 resultsVexday analysis
MLflow apresenta um perfil de risco contido com apenas 2 vulnerabilidades conhecidas, nenhuma em exploração ativa ou classificada como crítica. A fraqueza dominante é Cross-Site Scripting (CWE-79), típica de aplicações web, mas sem alertas recentes que indiquem urgência imediata de ação.
CVE-2026-2651CRITICALMissing Authorization Validation in mlflow/mlflowEPSS 0.3%CVE-2025-1474LOWWeak Password Requirements in mlflow/mlflowEPSS 0.3%CVE-2024-4263MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.3%CVE-2025-15381HIGHUnauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflowEPSS 0.3%CVE-2026-2393HIGHServer-Side Request Forgery (SSRF) in mlflow/mlflowEPSS 0.3%CVE-2026-3198MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.2%CVE-2026-33865MEDIUMStored XSS via unsafe YAML parsing in MLflowEPSS 0.2%CVE-2025-10279HIGHPrivilege Escalation in mlflow/mlflowEPSS 0.2%CVE-2026-71211HIGHmlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy EndpointEPSS 0.2%CVE-2025-1473MEDIUMCSRF in mlflow/mlflowEPSS 0.2%CVE-2025-14279HIGHDNS Rebinding Vulnerability in mlflow/mlflowEPSS 0.2%CVE-2026-4137HIGHIncomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflowEPSS 0.2%