VYPR

apk package

chainguard/mlflow-fips

pkg:apk/chainguard/mlflow-fips

Vulnerabilities (22)

  • CVE-2026-33865MedApr 7, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI

  • CVE-2026-0545CriApr 3, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_

Page 2 of 2