
[CIVN-2026-0416] Server-Side Request Forgery Vulnerability in MLflow
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Server-Side Request Forgery Vulnerability in MLflow
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
MLflow versions prior to 3.15.0
Overview
A vulnerability has been reported in MLflow that could allow an unauthenticated attacker to conduct Server-Side Request Forgery (SSRF) attacks and gain sensitive information on the targeted server.
Target Audience:
All organisations and individuals using affected MLflow.
Risk Assessment:
High risk of compromise of the cloud or enterprise environment.
Impact Assessment:
Potential for unauthorized access to internal services, exfiltrate sensitive metadata/credentials, and conduct internal reconnaissance.
Description
MLflow is an open-source platform designed to manage the machine learning lifecycle, providing capabilities for experiment tracking, model management, and deployment.
A vulnerability exists in MLflow due to improper input validation of user-supplied URIs/URLs within the MLflow application. An attacker can exploit this by submitting a specially crafted URL that points to internal resources rather than legitimate external storage or endpoints.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to conduct Server-Side Request Forgery (SSRF) attacks and gain sensitive information on the targeted server
Solution
Apply appropriate updates as mentioned by the vendor:
https://github.com/advisories/GHSA-7gwp-5pfp-969j
Vendor Information
MLflow
https://mlflow.org/
References
https://github.com/advisories/GHSA-7gwp-5pfp-969j
https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j
CVE Name
CVE-2026-64849
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqHDXwACgkQ3jCgcSdc
ys+BDQ//aopH/YA04rqu5yyL11SgalOB39/aieS6ltaDBXoR5IHiVFpHg2xabpZG
d2bERsS+Cgc/S00pZbkFfiLGt29gDPMajt6I9IF36do6M9s+q7Q0X4lUUbbaWQd1
3oUJUCGgFzRxnrzU99OI0cNHsZkvuhBsU5jcpdM4QO4PVg0gQf3KCStRQ1e4idPZ
ki1FBlUOcpSdoo3ggkLPqhUqDpecHYQwGJDDDaU49IZnpFjfJUMfOOihpd0X1pYy
Cr54ULTdeSzU0pmW8JkRgV5CJArDtRf28uLPSZV9loV1zC6Ky4hoM6sA6wIN1DbY
gyJjNGO0pzu6UgnovljaDe5SP6vd1eU9Ph9N4gXVJjhWiZyn4aeWsHYh3vqBd0+A
O7UQV7QUhMqV9lUsSvB4YX4nlm3OsjsGDfJxFrUUtsGvtdhDQF4qR+wrL8x6tMOw
mW2W45e1Sq2WKGaxcfeQ3BUeszCiK5IK0sXTADBEx0lzjJfFwoHfxvCOJiOA4crf
FxQTVuFHRmAiGA/BX1ksN8BpTgIgB/mQNjR+kzXP3NB8pTDdDKkTrT7LgYkOgWYa
JTBB3zunECsACS4nm4j8GWgr+AI3smLHAZadBt1EU89fM0eN86u2T/SimHwRFW6h
xYHJYGA2ACk8NOIxgvE14TJle+YSCYjtivcnT+q8Wx1UbR+eoME=
=/p4b
—–END PGP SIGNATURE—–


