lfprojects
14 known vulnerabilities affecting lfprojects products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-64849 | Act now | 16.4% | 9.3 | ● | MLflow is an open source AI engineering platform for agents, large language mode… |
| CVE-2026-0545 | High | 4.4% | 9.8 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not… | |
| CVE-2025-15379 | High | 2.4% | 10.0 | A command injection vulnerability exists in MLflow's model serving container ini… | |
| CVE-2026-2651 | High | 0.3% | 9.0 | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to m… | |
| CVE-2026-2614 | Medium | 3.6% | 7.5 | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handl… | |
| CVE-2026-0596 | Medium | 1.3% | 7.8 | A command injection vulnerability exists in mlflow/mlflow when serving a model w… | |
| CVE-2026-4035 | Medium | 0.5% | 7.7 | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolut… | |
| CVE-2026-34742 | Medium | 0.5% | 8.1 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Mod… | |
| CVE-2026-4137 | Medium | 0.2% | 7.8 | In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` fun… | |
| CVE-2026-2734 | Low | 0.4% | 6.5 | In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoi… | |
| CVE-2026-3198 | Low | 0.2% | 6.5 | MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authoriz… | |
| CVE-2026-34237 | Low | 0.2% | 6.1 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and cli… | |
| CVE-2026-35568 | Low | 0.1% | 5.7 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and cli… | |
| CVE-2026-10803 | Low | 0.1% | 3.6 | A flaw has been found in MLflow up to 3.10.0. This issue affects the function ml… |