ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.3

CVE-2026-64849 · MLflow Server-Side Request Forgery Vulnerability

Identyfikator
CVE-2026-64849
CVSS
9.3 CRITICAL
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
MLflow
Produkt
MLflow
Dodano do KEV
2026-08-19
Termin CISA
2026-09-02
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.