A security flaw has been identified in MLflow, a tool some users run on their hosting accounts to manage machine learning projects. The issue is a server-side request forgery (SSRF) vulnerability, which allows attackers to trick the MLflow tool into sending requests to services it is not intended to access.
If exploited, this flaw could let bad actors reach private internal services or cloud metadata services that are meant to be hidden from public access. Attackers could retrieve sensitive data from these services, including their response status and full response content, which may contain confidential information about your hosting environment or cloud resources.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849