À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2026-48710 · Kludex Starlette
CVE-2026-49869 · Kestra Kestra OSS
CVE-2026-59822 · BerriAI LiteLLM · CVSS 8.2
CVE-2026-82329 · JFrog Artifactory
accueil
veille
MLflow
éditeur
MLflow
1
vulnérabilité suivie
1
en exploitation active
1
critiques
19 août 2026
dernière publication
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-64849
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
MLflow
Critique
CVSS 9.3
19/08
← Retour à la veille
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer