CVE-2026-2651
published 2026-05-25CVE-2026-2651: A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled…
PriorityP357critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.34%
28.1th percentile
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | <= 3.10.1 | — |
| lfprojects | mlflow | >= 0 < 3.11.0rc1 | 3.11.0rc1 |
| mlflow | mlflow_mlflow | >= unspecified < 3.10.0 | 3.10.0 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv3.09.0CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
cvelistv5v3.09.0CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
ghsa5.3MEDIUM
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
ghsa·2026-06-09·CVSS 5.3
CVE-2026-47737 [MEDIUM] CWE-290 Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
### Impact
Puma is vulnerable to source IP spoofing when `set_remote_address proxy_protocol: :v1` is enabled and persistent connections are used.
PROXY protocol v1 is a connection-level protocol. [Support was added to Puma in v5.5.0](https://github.com/puma/puma/issues/2651). A proxy sends one PROXY header at the beginning of a TCP connection, before any HTTP data. Puma incorrectly re-parsed PROXY protocol headers after each keep-alive request on the same connection. An attacker able to send HTTP requests through a trusted proxy could therefore inject a second PROXY header between HTTP requests. Puma would treat the injected header as authoritative for the next request and overwrite `REMOTE_ADDR`.
This c
GHSA
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
ghsa·2026-06-08
CVE-2026-47736 [HIGH] CWE-400 Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
### Impact
[PROXY protocol support for Puma](https://github.com/puma/puma/issues/2651) was added in version 5.5.0.
When PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer. It waits for "\r\n" to determine whether a PROXY v1 line is present. If an attacker opens a TCP connection and continuously sends bytes without CRLF, Puma keeps appending to this pre-parse buffer.
This can cause unbounded in-process memory growth and additional CPU cost from repeatedly scanning the growing buffer for CRLF. A single, unauthenticated TCP connection can drive significant memory growth and may cause process/container OOM or degraded availability.
**Only Puma servers using the following non-default config a
GHSA
GHSA-8c7q-86fq-vvmh: A vulnerability in MLflow versions <=3
ghsa_unreviewed·2026-05-26
CVE-2026-2651 [CRITICAL] CWE-862 GHSA-8c7q-86fq-vvmh: A vulnerability in MLflow versions <=3
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
GHSA
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
ghsa·2026-05-26
CVE-2026-2651 [CRITICAL] CWE-862 MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
CVEList
Missing Authorization Validation in mlflow/mlflow
cvelistv5·2026-05-25·CVSS 9.0
CVE-2026-2651 [CRITICAL] CWE-862 Missing Authorization Validation in mlflow/mlflow
Missing Authorization Validation in mlflow/mlflow
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
VulDB
MLflow up to 3.9.x Multipart Upload /mlflow-artifacts/mpu/ authorization (EUVD-2026-31642)
vuldb·2026-05-25
CVE-2026-2651 [CRITICAL] MLflow up to 3.9.x Multipart Upload /mlflow-artifacts/mpu/ authorization (EUVD-2026-31642)
A vulnerability has been found in MLflow up to 3.9.x and classified as critical. This impacts an unknown function of the file /mlflow-artifacts/mpu/ of the component Multipart Upload Handler. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-2651. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
Red Hat
github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
vendor_redhat·2026-05-25·CVSS 9.0
CVE-2026-2651 [CRITICAL] CWE-1220 github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
A flaw was found in MLflow when the `--serve-artifacts` mode is enabled. A remote attacker can exploit this vulnerability due to insufficient resource-level permission checks for multipart upload (MPU) endpoints. This allows the attacker to overwrite artifacts belonging to other users, which can lead to model supply chain poisoning and potentially arbitrary code execution when compromised models are loaded.
Statement: No Red Hat products ship affected versions of mlflow.
Package: rhoai/odh-mlflow-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-run
No detection rules found.
No public exploits indexed.
https://github.com/mlflow/mlflow/commit/d7290811d8f3c95366d80109424edc1fb1ad966fhttps://huntr.com/bounties/65beb119-d3e0-4e03-af2f-fa98f78f83dchttps://access.redhat.com/security/cve/CVE-2026-2651https://bugzilla.redhat.com/show_bug.cgi?id=2481117https://huntr.com/bounties/65beb119-d3e0-4e03-af2f-fa98f78f83dchttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2651.json
2026-05-25
Published