MLflow Security Update Advisory (CVE-2026-64849)

MLflow Security Update Advisory (CVE-2026-64849)

Overview


A security update has been released to address CVE-2026-64849, a server-side request forgery (SSRF) vulnerability in MLflow (a vulnerability in which the server sends requests to internal or arbitrary addresses at the threat actor’s direction).

Affected Versions


  • MLflow version 3.14.0 And earlier.

Vulnerability Details


  • A server-side request forgery (SSRF) vulnerability (CVE-2026-64849) was identified in MLflow’s webhook forwarding process.
  • The advisory mentions an unauthenticated full-read SSRF and explains that it is possible to bypass the validatewebhook_url through unverified HTTP redirections and DNS rebinding.

Recommended Actions


  • A Vulnerability Patch has been provided via the latest update.
  • You must update to MLflow 3.15.0 Or later.

References