
⚠ HIGH PRIORITY — CISA KEV (Aug 18, 2026). CVE-2026-64849 is an unauthenticated server-side request forgery in MLflow webhook delivery. Attackers bypass _validate_webhook_url() via HTTP redirects or DNS rebinding to reach cloud metadata (169.254.169.254), internal admin APIs, and localhost services — with full response body returned via the /webhooks/{id}/test endpoint.
Affected MLflow
- MLflow versions before 3.15.0 (confirmed through 3.13.0)
- Default
mlflow serverwithout authentication on port 5000 - Linux GPU/ML training hosts with tracking server bound to
0.0.0.0 - Cloud VMs where IMDS credentials are reachable from the MLflow host
Check exposure
pip show mlflow | grep Version
ss -tlnp | grep 5000
curl -s http://127.0.0.1:5000/healthPatching Method
- Upgrade MLflow:
pip install 'mlflow>=3.15.0'in every venv and container. - Rebuild Docker images pinning
mlflow==3.15.0or later in requirements.txt. - Restart MLflow tracking server and all worker processes.
- Enable MLflow basic auth or place server behind OAuth reverse proxy.
- Block public access to port 5000 — use SSH tunnel or internal LB only.
- Rotate cloud IAM keys if tracking server was internet-exposed on vulnerable build.
- Audit webhook configs for attacker-controlled callback URLs.
pip install 'mlflow>=3.15.0' --upgrade
mlflow server --host 127.0.0.1 --port 5000Until patched
- Bind MLflow to
127.0.0.1only — never0.0.0.0without auth - Firewall port 5000 from WAN and untrusted VLANs
- Disable webhook test endpoint exposure via network segmentation
CVSS: 9.3 Critical. Fixed in MLflow 3.15.0 (PR #24258).