Python

mlflow

MLflow is an open source platform for the complete machine learning lifecycle

Apache-2.0

All Versions

Vulnerabilities (Public)

Known vulnerabilities and security issues detected in the extension's dependencies and code.

Vulnerability IDAdvisoryAffected Versions
CVE-2026-4035mlflow – Insertion of Sensitive Information Into Sent Data
Critical
< 3.11.0
CVE-2026-2651MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
Critical
< 3.11.0rc0
CVE-2026-2611mlflow – Origin Validation Error
Critical
== 3.9.0
CVE-2026-2652Affected versions of the mlflow package are vulnerable to Authentication Bypass due to incomplete enforcement of authentication middleware on non-gateway routes when the server is run with --app-name …
High
<3.11.0
CVE-2026-4137MLFlow Creates a Temporary File With Insecure Permissions
High
< 3.11.0
CVE-2026-2614MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
High
< 3.10.0
CVE-2026-2393MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
High
< 3.9.0
CVE-2026-3198mlflow – Improper Access Control
Medium
< 3.11.0rc0
CVE-2026-2734mlflow – Improper Access Control
Medium
< 3.10.0
CVE-2026-10803mlflow – Use of a Broken or Risky Cryptographic Algorithm
Low
< 3.10.1
Page 1

Safety Discovered Vulnerabilities

Additional security issues found by Safety, exclusive to our platform.

Safety discovered vulnerability data is available for Enterprise customers

Book a call with us to see Safety in action.

Vulnerable Functions

Functions linked to known vulnerabilities in this package.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.