CVE-CVE-2026-64849
Severity
CRITICAL
CVSS Score
9.3
Description
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and...
PoCs for CVE-CVE-2026-64849
CVE-2026-64849-PoC
General
0
codeb0ssx
2026-08-18
CVE-2026-64849
General
0
BiuTrap
2026-08-19
CVE-2026-64849-poc-lab
Buffer Overflow
Python
0
isaca0315
2026-09-06