MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • Thursday, 20th August, 2026
  • 04:04am

A security issue has been found in MLflow, a tool many users run on their hosting accounts to manage machine learning workflows for their websites or applications. This flaw is a server-side request forgery vulnerability, which lets bad actors manipulate the MLflow tool to send requests to internal systems or cloud metadata services that are usually locked away from public access. If this vulnerability is exploited, attackers can retrieve data from these restricted services, including the status of the requests and the actual content of data returned from those services. This could put sensitive information stored in your internal systems or cloud metadata at risk if you use MLflow as part of your hosted setup.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849

« Back