MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • Friday, 21st August, 2026
  • 04:04am

A security flaw has been found in MLflow, a tool used to manage machine learning projects and related workflows. This flaw is a server-side request forgery (SSRF) vulnerability, meaning attackers can trick the MLflow service into sending unauthorized requests on its own behalf.

This vulnerability lets bad actors use an affected MLflow instance to access internal systems or cloud metadata services that should be private and inaccessible from the public internet. If exploited, attackers can retrieve sensitive response status information and full response content from these private services.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849

« Back