MLflow security advisory (AV26-832)
Brief
Serial Number: AV26-832
Date: August 19, 2026
As of August 17, 2026, MLflow is affected by vulnerabilities in the following product:
- MLflow
- Prior to 3.15.0
On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Release v3.15.0
- mlflow/mlflow
- GitHub
- Unauthenticated full-read SSRF in MLflow webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
- Advisory
- mlflow/mlflow
- GitHub
- CISA KEV: CVE-2026-64849
MLflow security advisory (AV26-832) - Canadian Centre for Cyber Security
