Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://kb.cert.org/vuls/id/369093 |
|
Wed, 23 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mlflow
Mlflow mlflow |
|
| Vendors & Products |
Mlflow
Mlflow mlflow |
|
| Metrics |
cvssV3_1
|
Wed, 23 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 |
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact. | |
| Title | MLflow dspy bypasses pickle deserialization control | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-23T17:22:35.232Z
Reserved: 2026-09-23T16:17:27.934Z
Link: CVE-2026-96775
Updated: 2026-09-23T17:22:20.026Z
Status : Deferred
Published: 2026-09-23T17:17:25.407
Modified: 2026-09-23T18:17:12.323
Link: CVE-2026-96775
No data.
OpenCVE Enrichment
Updated: 2026-09-23T18:15:07Z