CVE-2025-0453

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:2.17.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-20 10:15

Updated : 2025-10-15 13:16


NVD link : CVE-2025-0453

Mitre link : CVE-2025-0453

CVE.ORG link : CVE-2025-0453


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-410

Insufficient Resource Pool

NVD-CWE-noinfo