FAIL › dossier
mlflow
PRODUCTDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-19 | CVE-2026-64849 | high | MLflow's server-side request forgery flaw lets attackers access internal cloud metadata services. |
| 2026-08-19 | CVE-2026-64849 | high | MLflow's server-side request forgery flaw lets attackers access internal cloud metadata services. |
| 2026-04-03 | CVE-2026-0545 | critical | CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not |
| 2026-03-30 | CVE-2025-15036 | critical | CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function w |
| 2026-03-30 | CVE-2025-15379 | critical | CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container ini |
| 2026-03-18 | CVE-2025-15031 | critical | CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file |