Direct Vulnerabilities

Known vulnerabilities in the mlflow package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<3.15.0-r1
  • L
GHSA-8ppf-4f7h-5ppj

<3.15.0-r1
  • L
GHSA-m4p7-r5rc-7g4j

<3.15.0-r1
  • L
Resource Exhaustion

<3.15.0-r1
  • L
Uncontrolled Memory Allocation

<3.14.0-r2
  • L
Uncontrolled Memory Allocation

<3.14.0-r2
  • L
Out-of-bounds Read

<3.14.0-r2
  • L
OS Command Injection

<3.14.0-r2
  • L
GHSA-phj9-mv4w-65pm

<3.14.0-r2
  • L
GHSA-3rp5-jjmw-4wv2

<3.14.0-r2
  • L
GHSA-v396-v7q4-x2qj

<3.14.0-r2
  • L
GHSA-r9mr-m37c-5fr3

<3.14.0-r2
  • L
Integer Overflow or Wraparound

<3.14.0-r2
  • L
GHSA-94p4-4cq8-9g67

<3.14.0-r2
  • L
GHSA-vjc4-5qp5-m44j

<3.14.0-r2
  • L
GHSA-956x-8gvw-wg5v

<3.14.0-r2
  • L
GHSA-62p4-gmf7-7g93

<3.14.0-r2
  • L
Resource Exhaustion

<3.14.0-r2
  • L
Uncontrolled Memory Allocation

<3.14.0-r2
  • L
GHSA-xj96-63gp-2gmr

<3.14.0-r2
  • L
GHSA-jjj6-mw9f-p565

<3.14.0-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.14.0-r2
  • L
Out-of-bounds Write

<3.14.0-r2
  • L
GHSA-5x94-69rx-g8h2

<3.14.0-r2
  • L
GHSA-2f96-g7mh-g2hx

<3.14.0-r2
  • L
GHSA-9hw9-ch79-4vh6

<3.14.0-r2
  • L
Uncontrolled Memory Allocation

<3.14.0-r2
  • L
GHSA-fjr4-x663-mwxc

<3.14.0-r2
  • L
GHSA-fj7v-r99m-22gq

<3.14.0-r2
  • L
Integer Overflow or Wraparound

<3.14.0-r2
  • L
GHSA-6r8x-57c9-28j4

<3.14.0-r2
  • H
Allocation of Resources Without Limits or Throttling

<3.14.0-r2
  • L
GHSA-rwj8-pgh3-r573

<3.14.0-r2
  • L
GHSA-4x4j-2g7c-83w6

<3.14.0-r2
  • L
GHSA-6p8h-3wgx-97gf

<3.14.0-r2
  • L
Out-of-bounds Read

<3.14.0-r2
  • L
GHSA-8v84-f9pq-wr9x

<3.14.0-r2
  • L
GHSA-45hq-cxwh-f6vc

<3.14.0-r2
  • L
GHSA-pg7v-jwj7-p798

<3.14.0-r2
  • L
Improper Initialization

<3.13.0-r1
  • L
Information Exposure

<3.13.0-r1
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<3.13.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.13.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.13.0-r1
  • L
GHSA-hpj7-wq8m-9hgp

<3.13.0-r1
  • L
GHSA-9x8q-7h8h-wcw9

<3.13.0-r1
  • L
Use of Incorrectly-Resolved Name or Reference

<3.13.0-r1
  • L
GHSA-537c-gmf6-5ccf

<3.13.0-r1
  • L
GHSA-82w8-qh3p-5jfq

<3.13.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.13.0-r1
  • L
GHSA-xcgm-r5h9-7989

<3.13.0-r1
  • L
GHSA-jp82-jpqv-5vv3

<3.13.0-r1
  • L
Improper Validation of Certificate with Host Mismatch

<3.13.0-r1
  • L
GHSA-g3cq-j2xw-wf74

<3.13.0-r1
  • L
GHSA-63hw-fmq6-xxg2

<3.13.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.13.0-r1
  • L
GHSA-2fqr-mr3j-6wp8

<3.13.0-r1
  • L
GHSA-4m7w-qmgq-4wj5

<3.13.0-r1
  • L
Improper Resource Shutdown or Release

<3.13.0-r1
  • L
GHSA-4fvr-rgm6-gqmc

<3.13.0-r1
  • M
Inefficient Regular Expression Complexity

<3.13.0-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.13.0-r0
  • M
Information Exposure

<3.13.0-r0
  • L
GHSA-65pc-fj4g-8rjx

<3.13.0-r0
  • L
GHSA-mf9v-mfxr-j63j

<3.13.0-r0
  • L
GHSA-qccp-gfcp-xxvc

<3.13.0-r0
  • L
GHSA-mv93-w799-cj2w

<3.12.0-r0
  • H
Directory Traversal

<3.11.1-r0
  • L
Cross-site Request Forgery (CSRF)

<3.11.1-r0
  • C
Arbitrary Argument Injection

<3.11.1-r0
  • L
OS Command Injection

<3.11.1-r0
  • L
GHSA-v92g-xgxw-vvmm

<3.11.1-r0
  • L
GHSA-jj8c-mmj3-mmgv

<3.11.1-r0
  • M
Missing Authorization

<3.11.1-r0
  • L
GHSA-46r5-x6jq-v8g6

<3.11.1-r0
  • M
Cross-site Scripting (XSS)

<3.11.1-r0
  • L
GHSA-fh64-r2vc-xvhr

<3.11.1-r0
  • L
GHSA-rpm5-65cw-6hj4

<3.11.1-r0
  • L
GHSA-x2qx-6953-8485

<3.11.1-r0
  • C
Missing Authentication for Critical Function

<3.12.0-r0
  • L
GHSA-7qhf-v65m-g5f3

<3.12.0-r0
  • M
Insecure Temporary File

<3.10.1-r1
  • L
GHSA-jr27-m4p2-rc6r

<3.10.1-r1
  • L
GHSA-gc5v-m9x4-r6x2

<3.10.1-r1
  • L
Uncontrolled Recursion

<3.10.1-r1
  • M
CVE-2026-26007

<3.9.0-r1
  • L
GHSA-g7f3-828f-7h7m

<3.4.0-r2
  • H
Resource Exhaustion

<2.21.0-r0
  • H
Out-of-bounds Write

<3.9.0-r1
  • L
GHSA-f9vj-2wh5-fj8j

<2.21.0-r0
  • L
GHSA-768j-98cg-p3fv

<3.6.0-r1
  • L
GHSA-hgf8-39gv-g3f2

<3.6.0-r1
  • L
GHSA-pq5p-34cr-23v9

<3.4.0-r2
  • M
Link Following

<3.8.0-r0
  • M
Improper Handling of Windows Device Names

<3.9.0-r1
  • M
Open Redirect

<3.1.0-r3
  • L
Insufficient Verification of Data Authenticity

<3.4.0-r1
  • L
GHSA-cfh3-3jmp-rvhc

<3.9.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.1.4-r0
  • L
Directory Traversal

<3.8.1-r3
  • M
Directory Traversal

<3.8.1-r3
  • L
GHSA-gm62-xv2j-4w53

<3.7.0-r1
  • L
GHSA-pq67-6m6q-mj2v

<3.1.0-r3
  • L
GHSA-8rrh-rw8j-w5fx

<3.8.1-r3
  • L
GHSA-63vm-454h-vhhq

<3.8.1-r3
  • L
Improper Input Validation

<3.4.0-r2
  • M
Open Redirect

<3.1.0-r3
  • L
GHSA-9ggr-2464-2j32

<3.4.0-r1
  • L
GHSA-29vq-49wr-vm6x

<3.9.0-r1
  • H
Improper Neutralization

<2.19.0-r2
  • L
GHSA-q34m-jh98-gwm2

<2.21.0-r0
  • L
GHSA-38jv-5279-wg99

<3.8.1-r1
  • L
Insufficiently Protected Credentials

<3.1.0-r0
  • L
GHSA-68rp-wp8r-4726

<3.9.0-r1
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.8.1-r1
  • L
GHSA-gmj6-6f8f-6699

<2.19.0-r2
  • L
Function Call With Incorrect Order of Arguments

<2.22.0-r2
  • M
Improper Handling of Windows Device Names

<3.6.0-r1
  • L
GHSA-w853-jp5j-5j7f

<3.8.0-r0
  • L
GHSA-4xh5-x5gv-qwph

<3.6.0-r0
  • M
Directory Traversal

<2.21.0-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.7.0-r1
  • L
CVE-2025-8869

<3.6.0-r0
  • H
CVE-2026-0994

<3.8.1-r3
  • L
GHSA-9hjg-9r4m-mvj7

<3.1.0-r0
  • L
GHSA-7gcm-g887-7qv7

<3.8.1-r3
  • L
GHSA-q2x7-8rv6-6q7h

<2.19.0-r2
  • L
Protection Mechanism Failure

<2.19.0-r2
  • L
GHSA-4grg-w6v8-c28g

<2.22.0-r2
  • L
Algorithmic Complexity

<3.5.1-r1
  • C
XML Injection

<3.6.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.8.1-r3
  • H
Allocation of Resources Without Limits or Throttling

<3.7.0-r1
  • L
GHSA-2xpw-w6gg-jr37

<3.7.0-r1
  • L
GHSA-r6ph-v2qm-q3c2

<3.9.0-r1
  • L
GHSA-2c2j-9gv5-cj73

<3.1.4-r0
  • L
GHSA-48p4-8xcf-vxj5

<3.1.0-r3
  • L
GHSA-7f5h-v6xp-fcq8

<3.5.1-r1
  • L
GHSA-58pv-8j8x-9vj2

<3.8.1-r3
  • M
Information Exposure Through Caching

<3.9.0-r1
  • L
Resource Exhaustion

<3.4.0-r2
  • H
Insufficient Verification of Data Authenticity

<2.14.2-r0
  • M
CVE-2024-37891

<2.14.1-r0
  • H
Arbitrary Code Injection

<2.13.2-r0
  • L
CVE-2024-35195

<2.13.1-r0