A security vulnerability has been found in MLflow, a common tool for managing machine learning projects on hosted servers. This is a server-side request forgery (SSRF) flaw, a type of issue that lets external attackers send unauthorized requests through the affected service.
When exploited, this vulnerability allows bad actors to trick MLflow into reaching private internal systems or cloud metadata services that are not meant to be accessible from the public internet. Attackers can then retrieve sensitive data including the status and full content of responses from these restricted services.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849