Weak Hash Issue in MLflow Dataset Digest Computation
CVE-2026-10803

2LOW

Key Information:

Vendor

MLflow

Status
Vendor
CVE Published:
4 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-10803?

A security vulnerability has been identified in MLflow affecting versions up to 3.10.0, specifically within the Dataset Digest Computation functionality. This flaw in the mlflow.data.digest_utils module results in the usage of a weak hashing algorithm, potentially allowing attackers to manipulate data integrity. The attack can be conducted locally and is considered to have high complexity, making its exploitation difficult. Although the issue was reported through a pull request, the project maintainers have yet to provide a response or release a patch. Organizations are advised to monitor this situation closely and implement preventive measures for their MLflow installations.

Affected Version(s)

MLflow 3.0

MLflow 3.1

MLflow 3.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dem0 (VulDB User)
VulDB CNA Team
.