MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • Thursday, 20th August, 2026
  • 10:04am

A security vulnerability has been found in MLflow, a tool many teams use to manage machine learning workflows and track experiment results. This flaw is a server-side request forgery, which lets attackers trick the MLflow server into sending requests to restricted systems it is not supposed to access.

If exploited, this issue allows attackers to reach internal company systems or cloud metadata services that are meant to be hidden from the public internet. The attacker can then retrieve the status and content of responses from these restricted services, which may include sensitive details about your cloud setup or internal network resources.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849

« Back