- Description
- MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- mlflow
CVSS 3.1
- Type
- Secondary
- Base score
- 9.3
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- MLflow Server-Side Request Forgery Vulnerability
- Exploit added on
- Aug 19, 2026
- Exploit action due
- Sep 2, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-918
- Hype score
- Not currently trending
Active Exploitation of MLflow Server-Side Request Forgery CRITICAL CVE-2026-64849 The Cybersecurity and Infrastructure Security Agency has added a critical server-side request forgery vulnerability in MLflow, tracked as **CVE-2026-64849** #KEV #CISA https://t.co/TSSWq9xIRW
@aspidaHQ
23 Aug 2026
9 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-77776 (CVSS 9.1): Headroom's LLM proxy (https://t.co/1Ym4mwuRlD) treats x-headroom-user-id as memory owner — no bind. Name another user's id → read/write stored LLM memory. Fixed in 0.36.1. CVE-2026-59279 + CVE-2026-64849 — no bind / no cap / no IP pin. #CVE #Pytho
@Innora_sg
21 Aug 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-64849 — Critical MLflow SSRF CVSS 9.3 • No authentication required • Public PoC available • Nuclei template released • Active exploitation confirmed • Add https://t.co/9ezaI4XmdN #CVE #CVE202664849 #MLflow #AI #SSRF #CyberSecurity #InfoSec #Exploit #P
@stem__shop
21 Aug 2026
1 Impression
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-64849 — MLflow, unauthenticated Server-Side Request Forgery (SSRF) to cloud credential theft CVSS: 9.3 | EPSS: 28% MLflow's webhook feature validates a URL once at registration but doesn't recheck it on delivery — letting an attacker redirect h
@YourDailyCVE
20 Aug 2026
47 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being
@CheckmarxZero
20 Aug 2026
76 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Added to CISA KEV — Detection and Remediation Guide… "On August 19, 2026, CISA added CVE-2026-64849, a Server-Side Request Forgery (SSRF)…" 🔗 https://t.co/lR53pz9fY6 #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesd
@SecurityAr58409
20 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New critical RCEs in MS QUIC (CVE-2026-62815) & Windows DNS (CVE-2026-62878) demand urgent patching to protect data. Also, MLflow SSRF (CVE-2026-64849) exposes internal services. Act now! #Cybersecurity #Vulnerabilities #NetSec
@YourAnon_irc
20 Aug 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-64849: MLflow SSRF Actively Exploited — Detection, Hunting, and Remedi… "On August 19, 2026, CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/VLyTH0KHp5 #CyberSecurity #ThreatIntel #cve202664849 #critical
@SecurityAr58409
20 Aug 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Heat Radar|2026/08/20 05:00 JST 今回は①CVE-2026-19490 Citrix NetScale…の件、②CVE-2026-64849 CISA KEV追加の件、③Windows IKE Extension RCE悪用の件を中心に、ほか4件を含めて音声で7件扱います。
@cyberheatradar
19 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-64849: SSRF Crítico en MLflow Permite Acceso a Servicios Internos y Metadatos Cloud Análisis técnico del CVE-2026-64849, vulnerabilidad SSRF crítica (CVSS 9.3) en MLflow explotada activamente. Impacto, mitigaciones y recomendaciones. https://t.co/EqP32NIrf9
@CiberPlanetaOrg
19 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: A public PoC is now available for CVE-2026-64849, an unauthenticated MLflow SSRF vulnerability rated CVSS 9.3. watchTowr reports that exploitation attempts have already been observed, increasing the risk for exposed MLflow deployments. 🔗 https://t.co/6YrvZsosG
@ThreatWire_
18 Aug 2026
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D762205E-C76F-495C-94C6-83DB1D4AF018",
"versionEndExcluding": "3.15.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]