{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-64849",
  "revision": 1,
  "title": "MLflow — Webhook Test Endpoint Server-Side Request Forgery",
  "summary": "MLflow's unauthenticated webhook test endpoint validates a webhook address once but then follows redirects to any host, so an attacker can make the server call internal or cloud metadata services and read back the response status and body.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.3,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
    "version": "3.1"
  },
  "epss": 0.1641,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-08-19",
    "prerequisites": "Network access to an MLflow tracking server older than 3.15.0; no credentials needed"
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "MLflow 3.15.0"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade MLflow to 3.15.0 or later and keep the tracking server off the public internet until then.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-64849",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-64849",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-64849",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64849",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/mlflow/mlflow/pull/24258"
    },
    {
      "type": "exploit",
      "url": "https://github.com/mlflow/mlflow/issues/24179"
    }
  ],
  "published_at": "2026-08-17T22:17:23.580Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "mlflow",
    "ssrf",
    "webhook",
    "cloud-metadata",
    "machine-learning"
  ]
}
