{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:70a216bb-6c02-55ea-8af8-0c8f492150c3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.9.1.post8+tuxcare",
      "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cccab2c9-fc25-5d72-b25e-38fe9d847bb4",
      "id": "CVE-2023-6709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bede4fe-3730-56d9-9e74-5db76d86d543",
      "id": "CVE-2023-6753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc0fd427-2bce-5f65-9834-975aef96bfa9",
      "id": "CVE-2023-6831",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b307e29-d7bf-5d64-abd8-ac58c96564ad",
      "id": "CVE-2023-6909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47e7615-dc7c-5a98-8761-4f46bd8e527e",
      "id": "CVE-2023-6940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6940 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae40c850-40a7-5a5f-9aa6-13155dfc998a",
      "id": "CVE-2023-6974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bd2dc48-1b40-543a-a276-7281be92ceeb",
      "id": "CVE-2023-6975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dcc626f-ba3a-55d5-9e22-69fd28b12426",
      "id": "CVE-2023-6976",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76742a55-7675-5ff9-8e6e-381fc6d374e0",
      "id": "CVE-2023-6977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6977 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a2eb59-9433-5363-ba52-1b4b9f5486a9",
      "id": "CVE-2024-1483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1483 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d119000b-f90e-5ed4-83c8-b1165b28aaf9",
      "id": "CVE-2024-1558",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post8+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b31d8e7-b847-51ca-a09b-4c36550b54e5",
      "id": "CVE-2024-1560",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87024af3-ab0e-5d68-b31a-1d7b9cbccacc",
      "id": "CVE-2024-1593",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391c0cbd-307d-5908-8bcc-5361e016d43b",
      "id": "CVE-2024-1594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57515bf9-ac96-58c9-b0e0-1bbc2db4ed2b",
      "id": "CVE-2024-27132",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea96469-e96f-59a2-a43e-5a2af03fdc11",
      "id": "CVE-2024-27133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ec14d6-8650-5b9b-8cac-be5b6578db82",
      "id": "CVE-2024-27134",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:019d9087-be1c-54cf-ba80-76eeefa190f0",
      "id": "CVE-2024-2928",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87cde2fd-5dfb-5d14-b033-9447e8312312",
      "id": "CVE-2024-3099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3099 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b320cb76-3f85-5a0b-8797-49e2cf95b327",
      "id": "CVE-2024-3573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc50b11-a206-50a0-8c4c-f7ebc3a7abb0",
      "id": "CVE-2024-37052",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3894db5c-91ca-585a-86ce-9259092967f8",
      "id": "CVE-2024-37053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49783301-7f2a-58ad-abc5-9b919ad85445",
      "id": "CVE-2024-37054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37054 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfda7837-c4db-5bbe-aa05-681f3e39f20e",
      "id": "CVE-2024-37055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbc8b273-1683-5a0d-8db9-d653818d8ce0",
      "id": "CVE-2024-37056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a0a6459-2a65-5ea0-917c-d3a8aff32bb9",
      "id": "CVE-2024-37057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37057 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b65c2003-422f-5d84-8758-57d93df172d7",
      "id": "CVE-2024-37058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee82e6a9-a962-5838-b7bb-2a6882073af4",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df75de6d-dfed-5ed8-88b6-4086c1fb8ec3",
      "id": "CVE-2024-37060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37060 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc5e9016-1748-52f0-9936-cd913f63d7f9",
      "id": "CVE-2024-37061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37061 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8347ca0e-7ecf-56d9-8a4a-9b822e0fd4fc",
      "id": "CVE-2024-4263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4263 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ebe5fee-6952-5dbf-9726-7c2dc4f1e657",
      "id": "CVE-2024-6838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f2b89ee-719d-51e4-9ab1-e84a08244379",
      "id": "CVE-2024-8859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d1b2764-8429-5395-9044-0f84fc71fd73",
      "id": "CVE-2025-0453",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cda909e-68bd-5b29-894d-621bfd423221",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98b0f26-af9a-548d-b691-8b0d63eea058",
      "id": "CVE-2025-11200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6442a308-24f2-59fc-846a-9aa732daf3de",
      "id": "CVE-2025-11201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb79601-6f0a-54b2-8f44-f112892605d6",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8734bfff-2f90-577b-93ab-d1d6592c40fa",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c7a4da-e060-5d80-86b4-7cc26b3f273c",
      "id": "CVE-2025-1474",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc5d3bb-0174-5080-ab98-3afe6ea10f81",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf370ec-06b5-5ab9-b520-93677a51b3eb",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post8+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bef9e57-9714-5a54-84ba-104b754be5c3",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post8+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37812f6b-3fbe-5582-a84e-4bd80fd52d9e",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae3c459c-7b87-5219-ad8e-610abb1b8554",
      "id": "CVE-2025-52967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:703e1b3e-ec5f-541d-a988-09194f3ecd64",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7160b7f-e0a7-5632-ad7d-efa2724127da",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00257a7c-372a-597f-b51a-581a9d35af26",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cedcee-cb92-5d75-a124-888ff8c68802",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4389800-e1dc-5f45-ba38-5c3f807f0035",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post8+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb9bb50-908a-5357-9425-d38fbc76ca94",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post8+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d844f27-5dd5-5d86-a5c8-6fbe79005bdc",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47db483b-736c-53f3-8cef-1b30ad0740f1",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2651 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50e2fe5-f602-5867-8946-5d304082b400",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post8+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42a375b3-8d13-5259-bac4-a2e884e90075",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43a5e0f6-faa3-5430-b177-302fbb39f7b3",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f4316ff-9680-50b5-9786-e228ebf5ab27",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c134a455-3d00-58d2-9198-71f5c3d14051",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33866 affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31123351-35aa-507c-aabb-e2bf65407557",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8edcd6-f397-5c28-a066-3a1031f7f035",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184966a3-fabb-5208-bd30-baef536bb53e",
      "id": "CVE-2026-64849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e09d319-43d8-5366-8440-800238fa4e6f",
      "id": "GHSA-gqvg-gmmx-x4hm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post8+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
    }
  ]
}