Kubeflow
Products
3- 6 CVEs
- 3 CVEs
- 2 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-54745 | Cri | 0.58 | 10.0 | — | Aug 28, 2026 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in… | ||
| CVE-2024-5552 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2024 | kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted… | ||
| CVE-2023-6570 | Med | 0.42 | 6.5 | 0.01 | Dec 14, 2023 | Server-Side Request Forgery (SSRF) in kubeflow/kubeflow | ||
| CVE-2023-6571 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow | ||
| CVE-2026-47237 | Hig | 0.00 | 8.0 | 0.00 | Jul 21, 2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from… | ||
| CVE-2024-9526 | Med | 0.00 | 5.4 | 0.00 | Nov 18, 2024 | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a… |
- risk 0.58cvss 10.0epss —
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in…
- risk 0.49cvss 7.5epss 0.01
kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted…
- risk 0.42cvss 6.5epss 0.01
Server-Side Request Forgery (SSRF) in kubeflow/kubeflow
- risk 0.40cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow
- risk 0.00cvss 8.0epss 0.00
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from…
- risk 0.00cvss 5.4epss 0.00
There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a…