THREAT OPS › CVEs › CVE-2026-64849
CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Vulnerability details
- Affected productsMLflow
- KEV remediation due2026-09-02
Related reporting
- August 2026 CVE Landscaperecordedfuture
- MLflow security advisory (AV26-832)cccs_ca
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-64849 — MLflow MLflow: MLflow Server-Side Request Forgery Vulnerabilitycisa_kev
- MLflow Bug Actively Exploited to Steal Credentialsduo_decipher
- [GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)github_advisories