CVE-2026-64849High· 8.5▾ Abyssal⚠ Exploited in the wildPoC availableA flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 46.8 · likelihood 3.3 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Federal remediation due Sep 2, 2026
0.3% → 16%
4 GitHub repos · Nuclei ×1
Last analysed / modified upstream
9.3 → 8.5
critical → high
Added to the CISA catalog on Aug 19, 2026. Federal remediation due Sep 2, 2026. View catalog ↗
A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates only the initial URL, but then follows unvalidated HTTP redirects, allowing the attacker to bypass security controls. Successful exploitation can lead to information disclosure, enabling access to internal or cloud metadata services and sensitive data.
mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) — rated Important by Red Hat. Released 2026-08-17, updated 2026-09-21.
Fixed:
Not affected:
For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520 For Red Hat OpenShift AI 3.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60367
Workarounds / mitigations:
Red Hat reports this vulnerability as exploited.
Affected packages:
mlflow < 3.15.0Patched in:
mlflow 3.15.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12243High· 7.5nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
CVE-2026-59197High· 8.2Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)