CVE Details
CVE-2026-64849
MLflow Server-Side Request Forgery Vulnerability
Published: 2026-08-19
CVSS: 9.3 CRITICAL
Product: MLflow MLflow
Due Date: 2026-09-02
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
GitHub PoC
Warning: GitHub PoC repositories are unverified. Some may be fake
or contain malware. Use caution and review code before running anything.
FIRST EPSS
EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.
Timeline
CVE Stalker
KEV
MITRE
GitHub
FIRST (EPSS)
MITRE
CVSS
SSVC
References
Show Raw Data
| Key | Remaining Key | Value |
|---|---|---|
| dataType | CVE_RECORD | |
| dataVersion | 5.2 | |
| cveMetadata > | cveId | CVE-2026-64849 |
| cveMetadata > | assignerOrgId | a0819718-46f1-4df5-94e2-005712e83aaa |
| cveMetadata > | state | PUBLISHED |
| cveMetadata > | assignerShortName | GitHub_M |
| cveMetadata > | dateReserved | 2026-07-20T18:31:39.290Z |
| cveMetadata > | datePublished | 2026-08-17T21:16:10.612Z |
| cveMetadata > | dateUpdated | 2026-08-19T17:47:59.618Z |
| containers > | cna > title | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) |
| containers > | cna > problemTypes > 0 > descriptions > 0 > cweId | CWE-918 |
| containers > | cna > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | cna > problemTypes > 0 > descriptions > 0 > description | CWE-918: Server-Side Request Forgery (SSRF) |
| containers > | cna > problemTypes > 0 > descriptions > 0 > type | CWE |
| containers > | cna > metrics > 0 > cvssV3_1 > attackComplexity | LOW |
| containers > | cna > metrics > 0 > cvssV3_1 > attackVector | NETWORK |
| containers > | cna > metrics > 0 > cvssV3_1 > availabilityImpact | NONE |
| containers > | cna > metrics > 0 > cvssV3_1 > baseScore | 9.3 |
| containers > | cna > metrics > 0 > cvssV3_1 > baseSeverity | CRITICAL |
| containers > | cna > metrics > 0 > cvssV3_1 > confidentialityImpact | HIGH |
| containers > | cna > metrics > 0 > cvssV3_1 > integrityImpact | LOW |
| containers > | cna > metrics > 0 > cvssV3_1 > privilegesRequired | NONE |
| containers > | cna > metrics > 0 > cvssV3_1 > scope | CHANGED |
| containers > | cna > metrics > 0 > cvssV3_1 > userInteraction | NONE |
| containers > | cna > metrics > 0 > cvssV3_1 > vectorString | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
| containers > | cna > metrics > 0 > cvssV3_1 > version | 3.1 |
| containers > | cna > references > 0 > name | https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j |
| containers > | cna > references > 0 > tags > 0 | x_refsource_CONFIRM |
| containers > | cna > references > 0 > url | https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j |
| containers > | cna > references > 1 > name | https://github.com/mlflow/mlflow/issues/24179 |
| containers > | cna > references > 1 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 1 > url | https://github.com/mlflow/mlflow/issues/24179 |
| containers > | cna > references > 2 > name | https://github.com/mlflow/mlflow/pull/24258 |
| containers > | cna > references > 2 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 2 > url | https://github.com/mlflow/mlflow/pull/24258 |
| containers > | cna > references > 3 > name | https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939 |
| containers > | cna > references > 3 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 3 > url | https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939 |
| containers > | cna > references > 4 > name | https://github.com/mlflow/mlflow/releases/tag/v3.15.0 |
| containers > | cna > references > 4 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 4 > url | https://github.com/mlflow/mlflow/releases/tag/v3.15.0 |
| containers > | cna > affected > 0 > vendor | mlflow |
| containers > | cna > affected > 0 > product | mlflow |
| containers > | cna > affected > 0 > versions > 0 > version | < 3.15.0 |
| containers > | cna > affected > 0 > versions > 0 > status | affected |
| containers > | cna > providerMetadata > orgId | a0819718-46f1-4df5-94e2-005712e83aaa |
| containers > | cna > providerMetadata > shortName | GitHub_M |
| containers > | cna > providerMetadata > dateUpdated | 2026-08-17T21:16:10.612Z |
| containers > | cna > descriptions > 0 > lang | en |
| containers > | cna > descriptions > 0 > value | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0. |
| containers > | cna > source > advisory | GHSA-7gwp-5pfp-969j |
| containers > | cna > source > discovery | UNKNOWN |
| containers > | adp > 0 > metrics > 0 > other > type | ssvc |
| containers > | adp > 0 > metrics > 0 > other > content > id | CVE-2026-64849 |
| containers > | adp > 0 > metrics > 0 > other > content > role | CISA Coordinator |
| containers > | adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation | active |
| containers > | adp > 0 > metrics > 0 > other > content > options > 1 > Automatable | yes |
| containers > | adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact | total |
| containers > | adp > 0 > metrics > 0 > other > content > version | 2.0.3 |
| containers > | adp > 0 > metrics > 0 > other > content > timestamp | 2026-08-19T17:44:03.944227Z |
| containers > | adp > 0 > references > 0 > url | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849 |
| containers > | adp > 0 > references > 0 > tags > 0 | government-resource |
| containers > | adp > 0 > title | CISA ADP Vulnrichment |
| containers > | adp > 0 > providerMetadata > orgId | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| containers > | adp > 0 > providerMetadata > shortName | CISA-ADP |
| containers > | adp > 0 > providerMetadata > dateUpdated | 2026-08-19T17:47:59.618Z |