🚨SEVERITY: CRITICAL — CVSS 9.3Security Advisory
TL;DR 📌
- MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
- Highest CVSS: 9.3 (Critical).
- Listed in CISA KEV (2026-08-19) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-64849.
What it is
CVE-2026-64849 is a server-side request forgery (SSRF) vulnerability in MLflow. The CVSS vector indicates the flaw is reachable over the network, requires no authentication and no user interaction, and can be exploited with low attack complexity.