A security flaw has been found in MLflow, a tool many hosting clients use to manage machine learning projects on their accounts. This is a server-side request forgery vulnerability, a type of issue that lets bad actors trick the MLflow software into sending requests to private, internal parts of your hosting environment or cloud metadata services that are not meant to be accessible to the public internet.
If exploited, this could let attackers pull sensitive information from those private services, including private data or configuration details that should stay secure. The information available about this flaw does not specify whether your hosting provider will address the issue automatically, or if users who run MLflow on their accounts need to take separate steps to fix it.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849