CVE lookup
CVE-2026-64849
Pruva has a verified reproduction for CVE-2026-64849: MLflow unauthenticated full-read SSRF in webhook delivery via redirect-follow bypass of _validate_webhook_url guard. The canonical evidence record is REPRO-2026-00335.
REPRO
REPRO-2026-00335
Package
mlflow/mlflow · PyPI
Severity
CRITICAL
Status
published