CVE-2026-64849

MLflow Server-Side Request Forgery Vulnerability

9.3
CVSS 3.1
9.8 %
EPSS (current)
2026-08-19
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: MLflow / MLflow

Published: 2026-08-17 · Due (CISA): 2026-09-02

CWE: CWE-918 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2026/CVE-2026-64849.yamlMLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass–

References only — no downloads or instructions.

Sources