OSS Support Hub / Machine Learning

Python Machine Learning Apache-2.0 Latest: model-catalog/latest

MLflow

Open source platform for the complete machine learning lifecycle

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

26.4K+439
GitHub Stars
📦
model-catalog/latest
Latest Release · 2 months ago
🔄
9d
Avg. Release Cadence
🐛
2.1K
Open Issues
📅
Yesterday
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-09

Known Vulnerabilities

10 active CVEs reported via OSV.dev

MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution

Published: 2024-02-24 Fixed in: 2.10.0

MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem

Published: 2026-05-11 Fixed in: 3.10.0

MLFlow unsafe deserialization

Published: 2024-06-04 No fix available

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

Published: 2026-04-07 Fixed in: 3.11.0rc0

MLflow Uncontrolled Resource Consumption vulnerability

Published: 2025-03-20 No fix available

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

Published: 2023-11-16 Fixed in: 2.8.0

MLflow has Weak Password Requirements

Published: 2025-03-20 Fixed in: 2.19.0

MLflow has a Local File Read/Path Traversal in dbfs

Published: 2025-03-20 Fixed in: 2.17.0rc0

mlflow Creates of Temporary File in Directory with Insecure Permissions

Published: 2026-02-02 Fixed in: 3.4.0rc0

Path traversal in MLflow

Published: 2023-12-15 Fixed in: 2.9.2

Alternatives to MLflow

Other Machine Learning projects in the Python ecosystem worth evaluating.

Support Options for MLflow

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for MLflow — without relying on volunteer maintainers.