A security vulnerability has been found in MLflow, a tool some website and application owners use on their hosting accounts to manage machine learning projects. The issue is a type of flaw called server-side request forgery. If attackers exploit this flaw, they can send requests from your MLflow setup to internal services on your hosting account, or to cloud metadata services that manage your hosting resources. They would be able to view the response status and full response content returned from those services.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849