← Back to CVE List
Vulnerability Analysis
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

CVE-2026-64849

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
Exploitability:3.9
Impact Score:4.8
Temporal Score:-
EPSS:1.11%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2026-08-19
Ransomware Use
Unknown
KEV Due Date
2026-09-02
VulnCheck In-the-Wild
No
Nuclei Template
YES
EPSS Score
1.109%
EPSS Percentile
63.3th pct
GitHub Severity
CRITICAL
SSVC Exploitation
Active
SSVC Automatable
Yes
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD