StackRadar

mlflow-server Helm chart

mlflowserver

Scored 14 Sept 2026

A Helm chart for MLFlow On Kubernetes

Latest 0.1.9 3 years agoapp version 2.1.1 1Artifact Hub

mlflow-server 0.1.9 deploys 3 container images: jwilder/dockerize, buntha/mlflow and bitnami/postgresql. Across the 2 measured, 396 findings7 critical, 11 high 8 on CISA KEV. The highest contribution is GHSA-7gwp-5pfp-969j in mlflow 2.1.1, fixed in 3.15.0.

Radar Score

5,80471199279

396 findings over 2 of 3 images measured

KEV ×8 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
jwilder/dockerizelatest00554502
buntha/mlflow2.1.1711942255,302
bitnami/postgresql14.5.0-debian-11-r21unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

99 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-j8r2-6x86-q33qrequests@2.28.12.31.0
MediumPYSEC-2026-3952gitpython@3.1.293.1.54
MediumGHSA-v9hf-5j83-6xpppymysql@1.0.21.1.1
MediumPYSEC-2023-192urllib3@1.26.132.0.6
MediumGHSA-cxfr-5q3r-2rc2mlflow@2.1.12.9.2
MediumGHSA-956x-8gvw-wg5vgitpython@3.1.293.1.51
MediumGHSA-xch3-2f9x-wh9fmlflow@2.1.13.8.0rc0
MediumGHSA-pqcv-qw2r-r859mlflow@2.1.1no fix listed
MediumGHSA-xg9f-g7g7-2323werkzeug@2.2.22.2.3
MediumGHSA-hq88-wg7q-gp4gmlflow@2.1.12.10.0
MediumPYSEC-2024-60idna@3.43.7
MediumGHSA-3v79-q7ph-j75hmlflow@2.1.12.10.0
MediumPYSEC-2026-2161gitpython@3.1.293.1.47
MediumDLA-4087-1python3.9@3.9.2-13.9.2-1+deb11u3
MediumGHSA-m2qf-hxjv-5gpqflask@2.2.22.2.5
MediumGHSA-cv6c-7963-wxcgmlflow@2.1.1no fix listed
MediumGHSA-6673-4983-2vx5fonttools@4.38.04.43.0
MediumGHSA-vhcx-3pq2-4fvcmlflow@2.1.13.9.0rc0
MediumDSA-5584-1bluez@5.55-3.15.55-3.1+deb11u1
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.45.00.52.0
MediumDLA-4057-1openssh@1:8.4p1-5+deb11u11:8.4p1-5+deb11u4
MediumGHSA-2xpw-w6gg-jr37urllib3@1.26.132.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@1.26.132.6.0
MediumGHSA-ghv6-9r9j-wh4jmlflow@2.1.1no fix listed
MediumGHSA-8ghj-p4vj-mr35pillow@9.3.010.0.0
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.45.00.52.0
MediumGHSA-q34m-jh98-gwm2werkzeug@2.2.23.0.6
MediumGHSA-vwhf-3v6x-wff8mlflow@2.1.12.9.0
MediumGHSA-5mvj-wmgj-7q8cmlflow@2.1.1no fix listed
MediumGHSA-fhff-qmm8-h2fpmlflow@2.1.13.9.0rc0
MediumPYSEC-2023-221werkzeug@2.2.22.3.8
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.45.00.52.0
MediumGHSA-r9mr-m37c-5fr3gitpython@3.1.293.1.54
MediumPYSEC-2024-230certifi@2022.12.72024.7.4
MediumGHSA-76cg-cfhx-373fmlflow@2.1.1no fix listed
MediumGHSA-x38x-g6gr-jqffmlflow@2.1.1no fix listed
MediumGHSA-43c4-9qgj-x742mlflow@2.1.1no fix listed
MediumGHSA-7p8j-qv6x-f4g4mlflow@2.1.1no fix listed
MediumGHSA-j8mg-pqc5-x9gjmlflow@2.1.1no fix listed
MediumGHSA-wf7f-8fxf-xfxcmlflow@2.1.1no fix listed
MediumGHSA-2h4p-vjrc-8xpqmako@1.2.41.3.12
MediumGHSA-284h-m62q-gf8wgitpython@3.1.293.1.59
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.45.00.52.0
MediumGHSA-g35p-px32-whv6mlflow@2.1.13.11.0
MediumGHSA-wvpp-8hx9-p66jgitpython@3.1.293.1.58
MediumGHSA-7gcm-g887-7qv7protobuf@4.21.125.29.6
MediumDLA-4445-1python3.9@3.9.2-13.9.2-1+deb11u4
MediumGHSA-j62r-wxqq-f3gfmlflow@2.1.12.12.1
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.4.80.6.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.9latest3 years ago2.1.1711992795,804

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/mlflowserver/mlflow-server.svg)](https://charts.stackradar.io/charts/mlflowserver/mlflow-server)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.