PyPI: mlflow

CVE-2026-10803

Safety vulnerability ID: SFTY-20260604-43273

Affected versions of the MLflow package are vulnerable to Insecure Randomness due to the use of weak hash functions in dataset digest computation. The `mlflow.data.digest_utils` function in `mlflow/data/digest_utils.py` employs deterministic sampling, which can lead to predictable hash collisions. An attacker can exploit this vulnerability by crafting specific datasets that result in hash collisions, potentially leading to data integrity issues or unauthorized data manipulation on the local host.

Created at: Jul 22, 2026Updated at: Jul 22, 2026

Overview

MLflow: Deterministic sampling in dataset digest enables predictable collisions

Advisory

mlflow – Use of a Broken or Risky Cryptographic Algorithm

Affected Package

Affecting mlflow package, versions
< 3.10.1

Also affects

---

How to Fix

Upgrade
mlflow
to
3.10.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more