THREATOPS
THREAT OPSCVEs › CVE-2026-64849

CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability

CISA KEVExploited: confirmedMLflow

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Vulnerability details

Related reporting