Hack The Sec - Leading Resource Of Linux Tutorial
[HIGH PRIORITY] MLflow Webhook SSRF Full-Read (CVE-2026-64849)

[HIGH PRIORITY] MLflow Webhook SSRF Full-Read (CVE-2026-64849)

MLflow patch for CVE-2026-64849 webhook SSRF

⚠ HIGH PRIORITY — CISA KEV (Aug 18, 2026). CVE-2026-64849 is an unauthenticated server-side request forgery in MLflow webhook delivery. Attackers bypass _validate_webhook_url() via HTTP redirects or DNS rebinding to reach cloud metadata (169.254.169.254), internal admin APIs, and localhost services — with full response body returned via the /webhooks/{id}/test endpoint.

Affected MLflow

  • MLflow versions before 3.15.0 (confirmed through 3.13.0)
  • Default mlflow server without authentication on port 5000
  • Linux GPU/ML training hosts with tracking server bound to 0.0.0.0
  • Cloud VMs where IMDS credentials are reachable from the MLflow host

Check exposure

pip show mlflow | grep Version
ss -tlnp | grep 5000
curl -s http://127.0.0.1:5000/health

Patching Method

  1. Upgrade MLflow: pip install 'mlflow>=3.15.0' in every venv and container.
  2. Rebuild Docker images pinning mlflow==3.15.0 or later in requirements.txt.
  3. Restart MLflow tracking server and all worker processes.
  4. Enable MLflow basic auth or place server behind OAuth reverse proxy.
  5. Block public access to port 5000 — use SSH tunnel or internal LB only.
  6. Rotate cloud IAM keys if tracking server was internet-exposed on vulnerable build.
  7. Audit webhook configs for attacker-controlled callback URLs.
pip install 'mlflow>=3.15.0' --upgrade
mlflow server --host 127.0.0.1 --port 5000

Until patched

  • Bind MLflow to 127.0.0.1 only — never 0.0.0.0 without auth
  • Firewall port 5000 from WAN and untrusted VLANs
  • Disable webhook test endpoint exposure via network segmentation

CVSS: 9.3 Critical. Fixed in MLflow 3.15.0 (PR #24258).

H

About the author

I am a Linux Administrator and Security Expert. Through this site I share Linux tutorials, hardening guides and security news.

Comments

↑