MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • Saturday, 22nd August, 2026
  • 22:04pm

A security flaw called server-side request forgery (SSRF) has been found in MLflow, a tool many website owners use to manage machine learning projects on their hosting servers.

If you use MLflow for your work, this vulnerability could let bad actors send requests from your MLflow setup to internal network services or cloud metadata services that are not intended to be accessible from the public internet. Attackers would also be able to see the status and content of the responses these services return.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849

« Back