Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
MLFlow unsafe deserialization
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
MLflow Uncontrolled Resource Consumption vulnerability
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
MLflow has Weak Password Requirements
MLflow has a Local File Read/Path Traversal in dbfs
mlflow Creates of Temporary File in Directory with Insecure Permissions
Path traversal in MLflow
MLflow Server-Side Request Forgery (SSRF)
Other Machine Learning projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for MLflow โ without relying on volunteer maintainers.
Talk to an Expert โ