Výsledky hledání

výrobce: MLflow× typ: zranitelnost× v celém archivu zrušit filtry

2 karet z 2 položek CZ · EN/orig

1

MLflow dspy and statsmodels flavors bypass pickle deserialization control

Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Exploitation of this vulnerability allows for arbitrary remote code execution…

MLflow FI

tg: zranitelnost tp: AI

· NCSC-FI · MLflow dspy and statsmodels flavors bypass pickle deserialization control

1

SPOJENO PŘES CVE CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

KEV ✓ EPSS 0.16 CVE-2026-64849 MLflow veřejná správa US CA

tg: zneužíváno tg: zranitelnost tg: regulace

· BleepingComputer · CISA warns of hackers exploiting critical MLflow vulnerability · Cyber Centre Kanada · MLflow security advisory (AV26-832) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)