PT-2026-46189 · Mlflow · Mlflow

·

CVE-2026-10803

·

Published

2026-06-04

·

Updated

2026-06-05

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions MLflow versions prior to 3.10.1
Description A flaw in the Dataset Digest Computation component allows for the use of a weak hash. This issue specifically affects the mlflow.data.digest utils() function within the mlflow/data/digest utils.py file. An attack can be launched on the local host, although it is characterized by high complexity and difficult exploitability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2026-10803
CVE-2026-10803
GHSA-5QMP-P3C4-72QJ
PYSEC-2026-195

Affected Products

Mlflow