PyPI package intelligence

mlflow Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the PyPI package mlflow, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
5
Known exploited vulnerabilities affecting mlflow
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
mlflow KEV with sensor-observed exploitation activity

Review mlflow exploitation against the versions you run

Four of the five exploited mlflow vulnerabilities tracked here are not in CISA KEV.

20%
Covered by CISA
80%
Beyond CISA

Attested mlflow vulnerabilities

5 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2026-2614

Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow

Beyond CISA 29 Aug 2026
CVE-2026-64849

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

In CISA 18 Aug 2026
CVE-2026-2652

Authentication Bypass in mlflow/mlflow

Beyond CISA 07 Aug 2026
CVE-2023-6909

Path Traversal: '\..\filename' in mlflow/mlflow

Beyond CISA 03 Jun 2026
CVE-2023-1177

Path Traversal: '\..\filename' in mlflow/mlflow

Beyond CISA 07 Jul 2025

Recurring weakness patterns

Path Traversal: '\..\filename', Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), and Authentication Bypass by Primary Weakness account for mapped occurrences across this mlflow KEV portfolio.

Browse all KEVs →