A security vulnerability has been discovered in MLflow, a tool some hosting clients use to track and manage machine learning project workflows. The flaw is classified as a server-side request forgery (SSRF) issue.
When exploited, this vulnerability could allow unauthorized attackers to trick the MLflow tool into sending requests to private internal systems or cloud metadata services that are not intended to be accessible from the public internet. If successful, the attacker would be able to receive both the status and full content of responses returned by these private services, which may include sensitive configuration details or other non-public information.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849