MLflow Security Update Advisory (CVE-2026-64849)
Overview A security update has been released to address CVE-2026-64849, a server-side request forgery (SSRF) vulnerability in MLflow (a vulnerability in which the server sends requests to internal or arbitrary addresses at the threat actor’s direction). Affected Versions MLflow version 3.14.0 And earlier. Vulnerability Details A server-side request forgery (SSRF)

