Weak Hash Issue in MLflow Dataset Digest Computation
CVE-2026-10803
Key Information:
Badges
What is CVE-2026-10803?
A security vulnerability has been identified in MLflow affecting versions up to 3.10.0, specifically within the Dataset Digest Computation functionality. This flaw in the mlflow.data.digest_utils module results in the usage of a weak hashing algorithm, potentially allowing attackers to manipulate data integrity. The attack can be conducted locally and is considered to have high complexity, making its exploitation difficult. Although the issue was reported through a pull request, the project maintainers have yet to provide a response or release a patch. Organizations are advised to monitor this situation closely and implement preventive measures for their MLflow installations.
Affected Version(s)
MLflow 3.0
MLflow 3.1
MLflow 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
