Kubeflow is a machine-learning platform and orchestration framework deployed within Kubernetes environments, with its vulnerability footprint concentrated in the core Kubeflow platform and Pipelines component. The recurring exposure centers on web-facing input-handling weaknesses including cross-site scripting, regular-expression denial-of-service conditions, and server-side request forgery, reflecting the application layer's role in orchestrating and exposing model training and deployment workflows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubeflow over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5552HIGH kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An atta | Jun 6, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-6571MEDIUM Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow | Dec 14, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-6570MEDIUM Server-Side Request Forgery (SSRF) in kubeflow/kubeflow | Dec 14, 2023 | 6.5 | 17 | NO | NO |
CVE-2024-9526MEDIUM There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a | Nov 18, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubeflow.
Media articles that mention a CVE ID that affects a product developed by Kubeflow — matched by CVE ID, not by vendor name.