OSS Support Hub / Machine Learning

Python Machine Learning Apache-2.0 Latest: ts/v0.2.0

MLflow

Open source platform for the complete machine learning lifecycle

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

โญ
25.9K+7
GitHub Stars
๐Ÿ“ฆ
ts/v0.2.0
Latest Release ยท Today
๐Ÿ”„
9d
Avg. Release Cadence
๐Ÿ›
2.1K
Open Issues
๐Ÿ“…
Today
Last Commit
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution

Published: 2024-02-24 Fixed in: 2.10.0

MLFlow unsafe deserialization

Published: 2024-06-04 No fix available

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

Published: 2026-04-07 No fix available

MLflow Uncontrolled Resource Consumption vulnerability

Published: 2025-03-20 No fix available

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

Published: 2023-11-16 Fixed in: 2.8.0

MLflow has Weak Password Requirements

Published: 2025-03-20 Fixed in: 2.19.0

MLflow has a Local File Read/Path Traversal in dbfs

Published: 2025-03-20 Fixed in: 2.17.0rc0

mlflow Creates of Temporary File in Directory with Insecure Permissions

Published: 2026-02-02 Fixed in: 3.4.0rc0

Path traversal in MLflow

Published: 2023-12-15 Fixed in: 2.9.2

MLflow Server-Side Request Forgery (SSRF)

Published: 2023-12-20 Fixed in: 2.9.2

Alternatives to MLflow

Other Machine Learning projects in the Python ecosystem worth evaluating.

Support Options for MLflow

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for MLflow โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’