MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Published 18 Aug 2026Updated 18 Aug 20269 sources
CVSS 0.0 △ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.