All Versions
Vulnerabilities (Public)
Known vulnerabilities and security issues detected in the extension's dependencies and code.
| Vulnerability ID | Advisory | Affected Versions | |||
|---|---|---|---|---|---|
| CVE-2026-4035 | mlflow – Insertion of Sensitive Information Into Sent Data | Critical | – | – | < 3.11.0 |
| CVE-2026-2651 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled | Critical | – | – | < 3.11.0rc0 |
| CVE-2026-2611 | mlflow – Origin Validation Error | Critical | – | – | == 3.9.0 |
| CVE-2026-2652 | Affected versions of the mlflow package are vulnerable to Authentication Bypass due to incomplete enforcement of authentication middleware on non-gateway routes when the server is run with --app-name … | High | – | – | <3.11.0 |
| CVE-2026-4137 | MLFlow Creates a Temporary File With Insecure Permissions | High | – | – | < 3.11.0 |
| CVE-2026-2614 | MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem | High | – | – | < 3.10.0 |
| CVE-2026-2393 | MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability | High | – | – | < 3.9.0 |
| CVE-2026-3198 | mlflow – Improper Access Control | Medium | – | – | < 3.11.0rc0 |
| CVE-2026-2734 | mlflow – Improper Access Control | Medium | – | – | < 3.10.0 |
| CVE-2026-10803 | mlflow – Use of a Broken or Risky Cryptographic Algorithm | Low | – | – | < 3.10.1 |
Page 1
Safety Discovered Vulnerabilities
Additional security issues found by Safety, exclusive to our platform.

