← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 18:35via Malware.news

MLflow security advisory (AV26-832)

Brief

Serial Number: AV26-832

Date: August 19, 2026

As of August 17, 2026, MLflow is affected by vulnerabilities in the following product:

  • MLflow
  • Prior to 3.15.0

On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

  • Release v3.15.0
  • mlflow/mlflow
  • GitHub
  • Unauthenticated full-read SSRF in MLflow webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
  • Advisory
  • mlflow/mlflow
  • GitHub
  • CISA KEV: CVE-2026-64849

MLflow security advisory (AV26-832) - Canadian Centre for Cyber Security

Read more on Malware.news