{"id":"CVE-2026-64849","title":"mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …","summary":"A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","cvssSource":"vendor","cwe":"CWE-918","vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["openshift_ai 3.4","openshift_ai 3.5"],"patched":["openshift_ai 3.4","openshift_ai 3.5"],"exploited":true,"published":"2026-08-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:25:11+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64849.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64849.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-64849"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517655"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64849"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64849"},{"url":"https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939"},{"url":"https://github.com/mlflow/mlflow/issues/24179"},{"url":"https://github.com/mlflow/mlflow/pull/24258"},{"url":"https://github.com/mlflow/mlflow/releases/tag/v3.15.0"},{"url":"https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:60367"},{"url":"https://github.com/advisories/GHSA-7gwp-5pfp-969j"}],"tags":["csaf","vex","red-hat","kev","in-the-wild","exploit-available","ghsa","pip"],"epss":0.1641,"epssPercentile":0.96889,"kev":true,"kevDateAdded":"2026-08-19","kevDueDate":"2026-09-02","kevRansomware":false,"exploits":{"github":4,"githubRepos":["https://github.com/codeb0ssx/CVE-2026-64849-PoC","https://github.com/BiuTrap/CVE-2026-64849","https://github.com/zavisco/CVE-2026-64849.yaml"],"nuclei":["CVE-2026-64849"],"checkedAt":"2026-09-21T15:48:23.890Z"},"exploitAvailable":true,"aliases":["GHSA-7gwp-5pfp-969j"],"ecosystem":"pip","scores":{"vendor":8.5,"ghsa":9.3},"ingestedAt":"2026-08-17T22:01:16.670Z","slug":"CVE-2026-64849","body":"## Overview\n\nA flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates only the initial URL, but then follows unvalidated HTTP redirects, allowing the attacker to bypass security controls. Successful exploitation can lead to information disclosure, enabling access to internal or cloud metadata services and sensitive data.\n\n## Vendor advisories\n\n- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)\n- **RHSA-2026:60367** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60367)\n\n**mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)** — rated Important by Red Hat. Released 2026-08-17, updated 2026-09-21.\n\nFixed:\n\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift AI 3.5\n\nNot affected:\n\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520\nFor Red Hat OpenShift AI 3.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60367\n\nWorkarounds / mitigations:\n\n- To reduce the attack surface for this vulnerability, restrict network access to the MLflow server. Implement firewall rules or network access controls to limit connectivity to the MLflow instance from untrusted networks. This operational control helps prevent unauthenticated attackers from reaching the vulnerable webhook test endpoint.\n\n## Exploitation\n\nRed Hat reports this vulnerability as exploited.\n\n## Package advisory (CVE-2026-64849)\n\nAffected packages:\n\n- `mlflow < 3.15.0`\n\nPatched in:\n\n- `mlflow 3.15.0`\n\nSource: https://github.com/advisories/GHSA-7gwp-5pfp-969j","depth":"abyssal","depthScore":75,"depthScoreParts":{"impact":46.8,"likelihood":3.3,"exploitation":25,"ransomware":0},"changes":[{"seq":208487,"id":"CVE-2026-64849","ts":1790005717890,"field":"cvss","old":"9.3","new":"8.5"},{"seq":208486,"id":"CVE-2026-64849","ts":1790005717890,"field":"severity","old":"critical","new":"high"},{"seq":5403,"id":"CVE-2026-64849","ts":1788887280631,"field":"exploit_available","old":"false","new":"true"},{"seq":4286,"id":"CVE-2026-64849","ts":1788886394666,"field":"exploit_available","old":"true","new":"false"},{"seq":3035,"id":"CVE-2026-64849","ts":1788883057966,"field":"exploit_available","old":"false","new":"true"},{"seq":2064,"id":"CVE-2026-64849","ts":1788882463140,"field":"exploit_available","old":"true","new":"false"},{"seq":1137,"id":"CVE-2026-64849","ts":1788881899545,"field":"exploit_available","old":"false","new":"true"},{"seq":183,"id":"CVE-2026-64849","ts":1787603679173,"field":"epss","old":"0.08154","new":"0.1641"},{"seq":156,"id":"CVE-2026-64849","ts":1787257348774,"field":"epss","old":"0.01109","new":"0.08154"},{"seq":138,"id":"CVE-2026-64849","ts":1787170773111,"field":"exploited","old":"false","new":"true"},{"seq":137,"id":"CVE-2026-64849","ts":1787170773111,"field":"kev","old":"false","new":"true"}]}