CVE-2025-0453
HIGHDescription
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| lfprojects | mlflow |
References
Frequently Asked Questions
What is CVE-2025-0453? +
How severe is CVE-2025-0453? +
What products are affected by CVE-2025-0453? +
How do I check if I'm vulnerable to CVE-2025-0453? +
Related Vulnerabilities
When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of …
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted …
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable …
ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected …
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote …