/Vulnerability Library

MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass

CVE-2026-64849
Verified

Description

MLflow > 3.15.0 contains an information disclosure vulnerability caused by improper validation of webhook URLs allowing attackers to reach internal or cloud metadata services and obtain response details, exploit requires unauthenticated access to the webhook test endpoint.

Severity

Critical

CVSS Score

9.3

Exploit Probability

10%

Published Date

August 18, 2026

Template Author

dhiyaneshdk

CVE-2026-64849.yaml
9.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVE ID:
cve-2026-64849
CWE ID:
cwe-918

References

https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969jhttps://github.com/mlflow/mlflow/pull/24258

Remediation Steps

Upgrade MLflow to a version containing PR #24258 which adds SSRFProtectedHTTPAdapter for connection-time IP validation covering redirect targets and DNS rebinding.