MEDIUM SEVERITYCONFIRMED
log_metric() silently stores NaN, inf, and -inf without raising
Package
mlflow
Version
3.10.1
Verified
2026-03-28
Description
mlflow's `_validate_metric()` uses `isinstance(v, numbers.Number)` which returns True for `float('nan')`, `float('inf')`, and `float('-inf')`. No `math.isfinite()` check is performed. All three values are stored silently. Downstream code reading metrics back may receive NaN without any indication the upstream call was semantically invalid. Different backends (SQLAlchemy, file store, REST) handle these values inconsistently.
Reproduction
from mlflow.utils.validation import _validate_metric
import math
_validate_metric('loss', float('nan'), 1000, 0) # no exception
_validate_metric('loss', float('inf'), 1000, 0) # no exception
_validate_metric('loss', float('-inf'), 1000, 0) # no exception
# All three values stored silently in the metrics database