PyPI: mlflow
CVE-2026-4035
Safety vulnerability ID: SFTY-20260603-99053
Affected versions of the `mlflow/mlflow` package are vulnerable to Improper Input Validation due to the resolution of environment variables in AI Gateway secrets. The `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime, leading to the inclusion of these resolved secrets in provider authentication headers sent to the configured upstream `api_base`. An attacker can exploit this by using low-privileged authenticated access in basic-auth deployments or unauthenticated access in default deployments without `basic-auth` to exfiltrate sensitive server-side environment credentials, potentially leading to artifact poisoning and cross-boundary code execution.
Overview
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
Advisory
mlflow – Insertion of Sensitive Information Into Sent Data
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260603-99053/CVE-2026-4035
- https://nvd.nist.gov/vuln/detail/CVE-2026-4035
- https://github.com/mlflow/mlflow/commit/4a3f2f720cb4f058c9e0c5b883e0acc9ab64a7f3
- https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233
- https://access.redhat.com/security/cve/CVE-2026-4035
- https://bugzilla.redhat.com/show_bug.cgi?id=2484318
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4035.json
- https://github.com/advisories/GHSA-g35p-px32-whv6
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
