Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-4137 |
|
Vulnerability in mlflow (CVE-2026-4137)
vulnerability in mlflow (CVE-2026-4137). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.0` or later.
|
| CVE-2026-0596 |
|
OS Command Injection in mlflow (CVE-2026-0596)
OS command injection in mlflow (CVE-2026-0596). Successful exploitation can lead to full system takeover. Exploitable via ``model_uri``. Mitigation: upgrade to `3.9.0` or later.
|