Vulnerability
Published 2026-08-19
Verified 2026-09-19

MLflow server-side request forgery (CVE-2026-64849)

CISA added CVE-2026-64849 to KEV on 19 August 2026. MLflow contains an SSRF issue that can let attackers reach internal or cloud metadata services. The CVE record states the issue is fixed in 3.15.0. Do not expose MLflow tracking servers to untrusted networks.

Product
MLflow
Versions
Prior to 3.15.0
CVSS
(CVSS 3.1, GitHub CNA)
Exploited in Australia?
unknown
Patch to
3.15.0

Primary: CVE record · Vendor: MLflow GHSA · CVE: CVE-2026-64849 · CISA KEV

tech ai