CVE-2025-0453

HIGH

mlflow 2.17.2 - Denial of Service via GraphQL Endpoint Resource Exhaustion

Title source: llm
STIX 2.1

Description

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-410
Status published
Products (2)
lfprojects/mlflow 2.17.2
pypi/mlflow 0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026