VYPR
Vendor

Kubeflow

Products
3
CVEs
6
Across products
11
Status
Private

Products

3

Recent CVEs

6
  • CVE-2026-54745CriAug 28, 2026
    risk 0.58cvss 10.0epss

    Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in…

  • CVE-2024-5552HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted…

  • CVE-2023-6570MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

  • CVE-2023-6571MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow

  • CVE-2026-47237HigJul 21, 2026
    risk 0.00cvss 8.0epss 0.00

    Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from…

  • CVE-2024-9526MedNov 18, 2024
    risk 0.00cvss 5.4epss 0.00

    There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a…