<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>MLflow on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/mlflow/</link>
    <description>Recent content in MLflow on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Wed, 19 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/mlflow/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>MLflow Server-Side Request Forgery Vulnerability</title>
      <link>https://www.phllaps.net/posts/mlflow-server-side-request-forgery-vulnerability/</link>
      <pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/mlflow-server-side-request-forgery-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.3&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.3 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-19) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-64849.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-64849 is a server-side request forgery (SSRF) vulnerability in MLflow. The CVSS vector indicates the flaw is reachable over the network, requires no authentication and no user interaction, and can be exploited with low attack complexity.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
