Denial of Service Vulnerability in MLflow by Databricks
CVE-2025-0453
What is CVE-2025-0453?
In MLflow version 2.17.2, the application contains a vulnerability at the /graphql endpoint that permits an attacker to execute a denial of service attack. By sending large batches of queries that continuously request all runs from a specified experiment, the attacker can monopolize all allocated workers within MLflow. This excessive consumption of resources prevents the application from responding to other legitimate user requests, thereby compromising its availability. Addressing this vulnerability is crucial to maintain optimal performance and security for MLflow users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mlflow/mlflow <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
