Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5523 articles · 192918 vulns · 37/41 feeds (7d)
← Back to list
9.3
CVE-2026-64849KEVEXPLOITEDPATCHED
mlflow · mlflow

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

Affected Products

VendorProductVersions
mlflowmlflowpip/mlflow: < 3.15.0

References

  • https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j(x_refsource_CONFIRM)
  • https://github.com/mlflow/mlflow/issues/24179(x_refsource_MISC)
  • https://github.com/mlflow/mlflow/pull/24258(x_refsource_MISC)
  • https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939(x_refsource_MISC)
  • https://github.com/mlflow/mlflow/releases/tag/v3.15.0(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB18h ago
CVE-2026-64849 | Mlflow up to 3.14.x Webhook Delivery validation.py _validate_webhook_url redirect
→ No new info (linked only)
CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
mlflow@3.15.0
CWECWE-918
PublishedAug 17, 2026
Trending Score90
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-69148
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
Trending: 25
MEDIUMCVE-2026-69146
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Trending: 22
NONECVE-2026-71211
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
Trending: 3
CRITICALCVE-2026-4035
Environment Variable Resolution Vulnerability in mlflow/mlflow
CRITICALCVE-2026-2651
Missing Authorization Validation in mlflow/mlflow

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Added to CISA KEV
Aug 17, 2026
Actively Exploited
Aug 17, 2026
Patch Available
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026