Mlflow

Vendor:

First CVE: Feb 23, 2022 · Active for 4 years

77
Total CVEs
More Total CVEs than 99% of tracked products
15.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mlflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2022
4 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

CVE Severity & Scoring

Mlflow77 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local7 (9.1%)
Network70 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (96.1%)
High3 (3.9%)
Unknown0 (0.0%)
User Interaction
None55 (71.4%)
Unknown0 (0.0%)
Required22 (28.6%)
Privileges Required
Low23 (29.9%)
High1 (1.3%)
None53 (68.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (77 CVEs).

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
Dec 18, 20237.579NOYES
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
Mar 24, 20239.879NOYES
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Jul 19, 202310.077NOYES
An attacker can overwrite any file on the server hosting MLflow without any authentication.
Nov 16, 20239.867NOYES
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the applicat
May 16, 20247.555NOYES
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerabili
Apr 3, 20269.850NOYES
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst
Oct 29, 20259.850NONO
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
Dec 5, 20237.547NOYES
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
May 17, 20239.846NOYES
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-n
May 15, 20268.645NOYES

Exploit Exposure

Signals from CVEs in this product scope (77 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
16 CVEs
20.8% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (77 CVEs).

Media Mentions

Signals from CVEs in this product scope (77 CVEs).

Top CNAs Publishing CVEs For Mlflow

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9.016.50.2%00
2.17.217.50.5%00
2.15.117.52.5%01
2.13.215.30.6%00