- Description
- MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- mlflow
CVSS 3.1
- Type
- Secondary
- Base score
- 9.3
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- MLflow Server-Side Request Forgery Vulnerability
- Exploit added on
- Aug 19, 2026
- Exploit action due
- Sep 2, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-918
- Hype score
- Not currently trending
🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being
@CheckmarxZero
20 Aug 2026
57 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Added to CISA KEV — Detection and Remediation Guide… "On August 19, 2026, CISA added CVE-2026-64849, a Server-Side Request Forgery (SSRF)…" 🔗 https://t.co/lR53pz9fY6 #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesd
@SecurityAr58409
20 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec
@YourAnon_irc
20 Aug 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Actively Exploited — Detection, Hunting, and Remedi… "On August 19, 2026, CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/VLyTH0KHp5 #CyberSecurity #ThreatIntel #cve202664849 #critical
@SecurityAr58409
20 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Heat Radar|2026/08/20 05:00 JST 今回は①CVE-2026-19490 Citrix NetScale…の件、②CVE-2026-64849 CISA KEV追加の件、③Windows IKE Extension RCE悪用の件を中心に、ほか4件を含めて音声で7件扱います。
@cyberheatradar
19 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-64849: SSRF Crítico en MLflow Permite Acceso a Servicios Internos y Metadatos Cloud Análisis técnico del CVE-2026-64849, vulnerabilidad SSRF crítica (CVSS 9.3) en MLflow explotada activamente. Impacto, mitigaciones y recomendaciones. https://t.co/EqP32NIrf9
@CiberPlanetaOrg
19 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: A public PoC is now available for CVE-2026-64849, an unauthenticated MLflow SSRF vulnerability rated CVSS 9.3. watchTowr reports that exploitation attempts have already been observed, increasing the risk for exposed MLflow deployments. 🔗 https://t.co/6YrvZsosG
@ThreatWire_
18 Aug 2026
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D762205E-C76F-495C-94C6-83DB1D4AF018",
"versionEndExcluding": "3.15.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]