Skip to content

CVE lookup

CVE-2026-64849

Pruva has a verified reproduction for CVE-2026-64849: MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard. The canonical evidence record is REPRO-2026-00335.

REPRO

REPRO-2026-00335

Package

mlflow/mlflow · PyPI

Severity

CRITICAL

Status

published