Database/AI/ML frameworks & serving
MLflow: basic-auth app leaves tracing and assessment endpoints without permission checks
Impact
When MLflow runs as mlflow server --app-name=basic-auth, the tracing and assessment endpoints are not wired to the permission validators that guard the rest of the API. Any authenticated user - including one holding NO_PERMISSIONS on the experiment - can read trace information for experiments they were never granted and create assessments against those traces. On a shared GPU cluster where MLflow is the common tracking server across teams, that exposes other tenants' trace metadata (prompts, run structure, model and dataset identifiers depending on what is logged) and lets an unprivileged account write misleading evaluation records into someone else's experiment. The vendor scores it confidentiality-low, integrity-high. Deployments not using the basic-auth app are not affected by this path.
Who can reach it
Any user with valid credentials on the MLflow basic-auth app, regardless of their experiment permissions. Network reach to the tracking server plus any account is enough.
What to do
The record does not name a fixed MLflow version - track the huntr report and the Red Hat VEX entry (MLflow is shipped in OpenShift AI) for the fix, then upgrade and restart the tracking server. Until a fixed build is available, treat every account on a basic-auth MLflow instance as able to read all traces: put the server behind an external authorizing proxy, or split teams across separate tracking servers rather than relying on in-app experiment permissions.
References
Related entries
- vLLM (`MediaConnector` SSRF): SSRF via `load_from_url` in multimodal input handlingCVE-2025-6242 · vLLM (`MediaConnector` SSRF)High
- vLLM (`Nemotron_Nano_VL_Config`): RCE via a config class evaluated at model loadCVE-2025-66448 · vLLM (`Nemotron_Nano_VL_Config`)High
- vLLM: remote media is fully materialized before size and per-prompt limits are enforcedCVE-2026-100650 · vLLM (media acquisition layer, audio_url/base64 chat path, batch speech runner, Rust frontend /tokenize)High
- vLLM: overlong token_ids on the disaggregated serving endpoint crash the workerCVE-2026-100651 · vLLM (disaggregated serving endpoint /inference/v1/generate, decoder prompt-length validation)High
- vLLM: out-of-range stop_token_ids trigger a CUDA device assertion and wedge EngineCoreCVE-2026-100654 · vLLM (OpenAI-compatible /v1/completions and /v1/chat/completions, stop_token_ids validation)High
- vLLM (`MediaConnector`): SSRF, recurrence of CVE-2025-6242CVE-2026-24779 · vLLM (`MediaConnector`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.