PyPI: mlflow

CVE-2026-4035

Safety vulnerability ID: SFTY-20260603-99053

Affected versions of the `mlflow/mlflow` package are vulnerable to Improper Input Validation due to the resolution of environment variables in AI Gateway secrets. The `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime, leading to the inclusion of these resolved secrets in provider authentication headers sent to the configured upstream `api_base`. An attacker can exploit this by using low-privileged authenticated access in basic-auth deployments or unauthenticated access in default deployments without `basic-auth` to exfiltrate sensitive server-side environment credentials, potentially leading to artifact poisoning and cross-boundary code execution.

Created at: Jul 21, 2026Updated at: Jul 21, 2026

Overview

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

Advisory

mlflow – Insertion of Sensitive Information Into Sent Data

Affected Package

Affecting mlflow package, versions
< 3.11.0

Also affects

---

How to Fix

Upgrade
mlflow
to
3.11.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more