VYPR

apk package

chainguard/mlflow-fips

pkg:apk/chainguard/mlflow-fips

Vulnerabilities (26)

  • CVE-2026-44244HigMay 7, 2026
    affected < 3.12.0-r0fixed 3.12.0-r0

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines

  • CVE-2026-42284HigMay 7, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (st

  • CVE-2026-42215HigMay 7, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass tha

  • CVE-2026-33866MedApr 7, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are no

  • CVE-2026-33865MedApr 7, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI

  • CVE-2026-0545CriApr 3, 2026
    affected < 3.11.1-r0fixed 3.11.1-r0

    In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_

Page 2 of 2