MLflow

4 known vulnerabilities in MLflow, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-64849 CVSS 9.3 critical · actively exploited MLflow Server-Side Request Forgery Vulnerability

Latest vulnerabilities

  • CVE-2026-96804 CVSS 8.8 high MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in…
  • CVE-2026-96775 CVSS 8.8 high MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path…
  • CVE-2026-79721 CVSS 8.6 high Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact…
  • CVE-2026-64849 CVSS 9.3 critical · actively exploited MLflow Server-Side Request Forgery Vulnerability