Latest
Alerts
Security
DevOps
Cloud
AI
Self-hosted
Linux
Networking
Search
⌘K
FR
live
CVE-2026-48710 · Kludex Starlette
CVE-2026-49869 · Kestra Kestra OSS
CVE-2026-59822 · BerriAI LiteLLM · CVSS 8.2
CVE-2026-82329 · JFrog Artifactory
home
alerts
MLflow
vendor
MLflow
1
vulnerability tracked
1
under active exploitation
1
critical
19 August 2026
latest publication
cve
Vulnerability watch
id
vulnerability
severity
published
CVE-2026-64849
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
MLflow
Critical
CVSS 9.3
19/08
← Back to the watch
esc
Type at least two characters.
↑
↓
navigate
↵
open
esc
dismiss