A security flaw has been identified in MLflow, a tool many website owners use to manage machine learning workflows on their hosting accounts. This flaw is a server-side request forgery (SSRF) vulnerability, which lets attackers use your MLflow setup to send requests to systems that are supposed to be private and not accessible from the public internet.
These private systems include internal network services and cloud metadata services. If you run MLflow on your hosting, an attacker could exploit this flaw to reach these services and retrieve their response status and content.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849