{"id":"CGA-87g5-9ghj-vgx3","modified":"2026-09-11T05:32:12.729134121Z","published":"2026-09-01T12:53:31Z","upstream":["CVE-2026-71211","GHSA-h7x2-h6g9-p789"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71211"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/96b7d900e14227e0821981409d86f5fb6c59b386"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/tree/v3.14.0/mlflow"}],"affected":[{"package":{"name":"mlflow-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/mlflow-fips?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.16.0-r0"}]}],"ecosystem_specific":{"components":[{"component_type":"python","component_location":"/usr/local/lib/python3.10/site-packages/mlflow-3.15.1.dist-info/METADATA","component_purl":"pkg:pypi/mlflow@3.15.1","latest_event_status":"fixed","latest_event_timestamp":"2026-09-10T13:30:48Z","component_name":"mlflow","component_version":"3.15.1"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-87g5-9ghj-vgx3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}