MLflow Security Update Advisory (CVE-2026-64849)
Overview
A security update has been released to address CVE-2026-64849, a server-side request forgery (SSRF) vulnerability in MLflow (a vulnerability in which the server sends requests to internal or arbitrary addresses at the threat actor’s direction).
Affected Versions
- MLflow version 3.14.0 And earlier.
Vulnerability Details
- A server-side request forgery (SSRF) vulnerability (CVE-2026-64849) was identified in MLflow’s webhook forwarding process.
- The advisory mentions an unauthenticated full-read SSRF and explains that it is possible to bypass the
validatewebhook_urlthrough unverified HTTP redirections and DNS rebinding.
Recommended Actions
- A Vulnerability Patch has been provided via the latest update.
- You must update to MLflow 3.15.0 Or later.