CVE Details

CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability
Published: 2026-08-19 CVSS: 9.3 CRITICAL Product: MLflow MLflow Due Date: 2026-09-02

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.3
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-64849
cveMetadata > assignerOrgId a0819718-46f1-4df5-94e2-005712e83aaa
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName GitHub_M
cveMetadata > dateReserved 2026-07-20T18:31:39.290Z
cveMetadata > datePublished 2026-08-17T21:16:10.612Z
cveMetadata > dateUpdated 2026-08-19T17:47:59.618Z
containers > cna > title MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-918
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-918: Server-Side Request Forgery (SSRF)
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact NONE
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.3
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact LOW
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV3_1 > scope CHANGED
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > references > 0 > name https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j
containers > cna > references > 0 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 0 > url https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j
containers > cna > references > 1 > name https://github.com/mlflow/mlflow/issues/24179
containers > cna > references > 1 > tags > 0 x_refsource_MISC
containers > cna > references > 1 > url https://github.com/mlflow/mlflow/issues/24179
containers > cna > references > 2 > name https://github.com/mlflow/mlflow/pull/24258
containers > cna > references > 2 > tags > 0 x_refsource_MISC
containers > cna > references > 2 > url https://github.com/mlflow/mlflow/pull/24258
containers > cna > references > 3 > name https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939
containers > cna > references > 3 > tags > 0 x_refsource_MISC
containers > cna > references > 3 > url https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939
containers > cna > references > 4 > name https://github.com/mlflow/mlflow/releases/tag/v3.15.0
containers > cna > references > 4 > tags > 0 x_refsource_MISC
containers > cna > references > 4 > url https://github.com/mlflow/mlflow/releases/tag/v3.15.0
containers > cna > affected > 0 > vendor mlflow
containers > cna > affected > 0 > product mlflow
containers > cna > affected > 0 > versions > 0 > version < 3.15.0
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > providerMetadata > orgId a0819718-46f1-4df5-94e2-005712e83aaa
containers > cna > providerMetadata > shortName GitHub_M
containers > cna > providerMetadata > dateUpdated 2026-08-17T21:16:10.612Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
containers > cna > source > advisory GHSA-7gwp-5pfp-969j
containers > cna > source > discovery UNKNOWN
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > id CVE-2026-64849
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-08-19T17:44:03.944227Z
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-19T17:47:59.618Z