[CIVN-2026-0416] Server-Side Request Forgery Vulnerability in MLflow

By Published On: August 20, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Server-Side Request Forgery Vulnerability in MLflow


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


MLflow versions prior to 3.15.0

Overview


A vulnerability has been reported in MLflow that could allow an unauthenticated attacker to conduct Server-Side Request Forgery (SSRF) attacks and gain sensitive information on the targeted server.


Target Audience:

All organisations and individuals using affected MLflow.


Risk Assessment:

High risk of compromise of the cloud or enterprise environment.


Impact Assessment:

Potential for unauthorized access to internal services, exfiltrate sensitive metadata/credentials, and conduct internal reconnaissance.


Description


MLflow is an open-source platform designed to manage the machine learning lifecycle, providing capabilities for experiment tracking, model management, and deployment.


A vulnerability exists in MLflow due to improper input validation of user-supplied URIs/URLs within the MLflow application. An attacker can exploit this by submitting a specially crafted URL that points to internal resources rather than legitimate external storage or endpoints.


Successful exploitation of this vulnerability could allow an unauthenticated attacker to conduct Server-Side Request Forgery (SSRF) attacks and gain sensitive information on the targeted server


Solution


Apply appropriate updates as mentioned by the vendor:

https://github.com/advisories/GHSA-7gwp-5pfp-969j



Vendor Information


MLflow

https://mlflow.org/


References


 

https://github.com/advisories/GHSA-7gwp-5pfp-969j

https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j


CVE Name

CVE-2026-64849




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqHDXwACgkQ3jCgcSdc

ys+BDQ//aopH/YA04rqu5yyL11SgalOB39/aieS6ltaDBXoR5IHiVFpHg2xabpZG

d2bERsS+Cgc/S00pZbkFfiLGt29gDPMajt6I9IF36do6M9s+q7Q0X4lUUbbaWQd1

3oUJUCGgFzRxnrzU99OI0cNHsZkvuhBsU5jcpdM4QO4PVg0gQf3KCStRQ1e4idPZ

ki1FBlUOcpSdoo3ggkLPqhUqDpecHYQwGJDDDaU49IZnpFjfJUMfOOihpd0X1pYy

Cr54ULTdeSzU0pmW8JkRgV5CJArDtRf28uLPSZV9loV1zC6Ky4hoM6sA6wIN1DbY

gyJjNGO0pzu6UgnovljaDe5SP6vd1eU9Ph9N4gXVJjhWiZyn4aeWsHYh3vqBd0+A

O7UQV7QUhMqV9lUsSvB4YX4nlm3OsjsGDfJxFrUUtsGvtdhDQF4qR+wrL8x6tMOw

mW2W45e1Sq2WKGaxcfeQ3BUeszCiK5IK0sXTADBEx0lzjJfFwoHfxvCOJiOA4crf

FxQTVuFHRmAiGA/BX1ksN8BpTgIgB/mQNjR+kzXP3NB8pTDdDKkTrT7LgYkOgWYa

JTBB3zunECsACS4nm4j8GWgr+AI3smLHAZadBt1EU89fM0eN86u2T/SimHwRFW6h

xYHJYGA2ACk8NOIxgvE14TJle+YSCYjtivcnT+q8Wx1UbR+eoME=

=/p4b

—–END PGP SIGNATURE—–

Share this article