A security vulnerability has been identified in MLflow, a popular tool used to manage machine learning workflows that many website and application owners run as part of their hosted services. The flaw is a server-side request forgery issue, which could allow attackers to trick the MLflow tool into sending requests to internal systems or cloud metadata services that are not intended to be reachable from the public internet. If exploited, this could let bad actors access sensitive data from those internal services, including their response status details and the content of their response bodies.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849