mlflow

Direct Vulnerabilities

Known vulnerabilities in the mlflow package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Certificate Validation

<3.14.0-r1
  • L
Resource Exhaustion

<3.14.0-r1
  • L
Improper Certificate Validation

<3.14.0-r1
  • L
Incorrect Privilege Assignment

<3.14.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.14.0-r1
  • C
Arbitrary Argument Injection

<3.15.2-r0
  • H
External Control of File Name or Path

<3.15.2-r0
  • M
Arbitrary Argument Injection

<3.15.2-r0
  • M
External Control of File Name or Path

<3.15.2-r0
  • H
Directory Traversal

<3.15.2-r0
  • L
CVE-2026-71211

<3.16.0-r0
  • L
Algorithmic Complexity

<3.15.2-r0
  • L
GHSA-gqvg-gmmx-x4hm

<3.15.0-r0
  • L
GHSA-hmq2-w58f-27jc

<3.15.2-r0
  • L
GHSA-4gmw-gg2m-w46p

<3.15.2-r0
  • L
GHSA-wvpp-8hx9-p66j

<3.15.2-r0
  • L
Inefficient Regular Expression Complexity

<3.15.2-r0
  • L
GHSA-jm78-9fvv-mhgr

<3.15.2-r0
  • L
Resource Exhaustion

<3.15.2-r0
  • L
GHSA-hh9p-6wh2-4mfc

<3.15.2-r0
  • L
Arbitrary Code Injection

<3.15.2-r0
  • L
Algorithmic Complexity

<3.15.2-r0
  • L
GHSA-9rj7-rf2p-w77r

<3.15.2-r0
  • L
Missing Authorization

<3.15.0-r0
  • L
Missing Authorization

<3.15.0-r0
  • L
Server-Side Request Forgery (SSRF)

<3.15.0-r0
  • L
Information Exposure

<3.14.0-r1
  • L
GHSA-3f7w-8rr8-f37f

<3.15.0-r0
  • L
HTTP Request Smuggling

<3.14.0-r1
  • L
Out-of-bounds Read

<3.15.0-r0
  • L
GHSA-p538-c434-8v24

<3.15.0-r0
  • M
Missing Authorization

*
  • L
Improper Input Validation

<3.14.0-r1
  • L
GHSA-539m-9xh6-q6rr

<3.15.0-r0
  • L
Resource Exhaustion

<3.14.0-r1
  • L
GHSA-3rp5-jjmw-4wv2

<3.14.0-r1
  • L
GHSA-6p8h-3wgx-97gf

<3.14.0-r1
  • L
GHSA-94p4-4cq8-9g67

<3.14.0-r1
  • L
GHSA-fjr4-x663-mwxc

<3.14.0-r1
  • L
GHSA-r9mr-m37c-5fr3

<3.14.0-r1
  • H
Allocation of Resources Without Limits or Throttling

<3.14.0-r1
  • L
Uncontrolled Memory Allocation

<3.14.0-r1
  • L
Out-of-bounds Read

<3.14.0-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.14.0-r1
  • L
GHSA-956x-8gvw-wg5v

<3.14.0-r1
  • L
Uncontrolled Memory Allocation

<3.14.0-r1
  • L
Resource Exhaustion

<3.14.0-r1
  • L
Integer Overflow or Wraparound

<3.14.0-r1
  • L
Resource Exhaustion

<3.14.0-r1
  • L
Out-of-bounds Write

<3.14.0-r1
  • L
Integer Overflow or Wraparound

<3.14.0-r1
  • L
OS Command Injection

<3.14.0-r1
  • L
Uncontrolled Memory Allocation

<3.14.0-r1
  • L
GHSA-rwj8-pgh3-r573

<3.14.0-r1
  • L
GHSA-v396-v7q4-x2qj

<3.14.0-r1
  • C
Out-of-bounds Read

<3.14.0-r1
  • L
Uncontrolled Memory Allocation

<3.14.0-r1
  • L
GHSA-2f96-g7mh-g2hx

<3.14.0-r1
  • L
Resource Exhaustion

<3.14.0-r1
  • C
Missing Authentication for Critical Function

*