CVE-2026-64849

Published Aug 17, 2026

Last updated 2 hours ago

Overview

Description
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
Source
security-advisories@github.com
NVD status
Analyzed
Products
mlflow

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.3
Impact score
4.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
MLflow Server-Side Request Forgery Vulnerability
Exploit added on
Aug 19, 2026
Exploit action due
Sep 2, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security-advisories@github.com
CWE-918

Social media

Hype score
Not currently trending
  1. 🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being

    @CheckmarxZero

    20 Aug 2026

    57 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Added to CISA KEV — Detection and Remediation Guide… "On August 19, 2026, CISA added CVE-2026-64849, a Server-Side Request Forgery (SSRF)…" 🔗 https://t.co/lR53pz9fY6 #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesd

    @SecurityAr58409

    20 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec

    @YourAnon_irc

    20 Aug 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Actively Exploited — Detection, Hunting, and Remedi… "On August 19, 2026, CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/VLyTH0KHp5 #CyberSecurity #ThreatIntel #cve202664849 #critical

    @SecurityAr58409

    20 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Cyber Heat Radar|2026/08/20 05:00 JST 今回は①CVE-2026-19490 Citrix NetScale…の件、②CVE-2026-64849 CISA KEV追加の件、③Windows IKE Extension RCE悪用の件を中心に、ほか4件を含めて音声で7件扱います。

    @cyberheatradar

    19 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ CVE-2026-64849: SSRF Crítico en MLflow Permite Acceso a Servicios Internos y Metadatos Cloud Análisis técnico del CVE-2026-64849, vulnerabilidad SSRF crítica (CVSS 9.3) en MLflow explotada activamente. Impacto, mitigaciones y recomendaciones. https://t.co/EqP32NIrf9

    @CiberPlanetaOrg

    19 Aug 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CRITICAL: A public PoC is now available for CVE-2026-64849, an unauthenticated MLflow SSRF vulnerability rated CVSS 9.3. watchTowr reports that exploitation attempts have already been observed, increasing the risk for exposed MLflow deployments. 🔗 https://t.co/6YrvZsosG

    @ThreatWire_

    18 Aug 2026

    25 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations