MLflow has an unauthenticated SSRF (CVE-2026-64849, CVSS 9.3) that reaches cloud metadata and returns the response, so it reads your instance credentials. Every version before 3.15.0 is affected. Now

MLflow has an unauthenticated SSRF (CVE-2026-64849, CVSS 9.3) that reaches cloud metadata and returns the response, so it reads your instance credentials. Every version before 3.15.0 is affected. Now on CISA's KEV list. Patch to 3.15.0 and enforce IMDSv2. https:// suriq.io/blog/mlflow-ssrf-cve- 2026-64849-cloud-metadata # CVE # CloudSecurity # DataBreach # Phishing

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

MLflow has an unauthenticated SSRF (CVE-2026-64849, CVSS 9.3) that reaches cloud metadata and returns the response, so it reads your instance credentials. Every version before 3.15.0 is affected. Now

mastodon:infosec-exchangeother41d ago kagi ↗

MLflow has an unauthenticated SSRF (CVE-2026-64849, CVSS 9.3) that reaches cloud metadata and returns the response, so it reads your instance credentials. Every version before 3.15.0 is affected. Now on CISA's KEV list. Patch to 3.15.0 and enforce IMDSv2. https:// suriq.io/blog/mlflow-ssrf-cve- 2026-64849-cloud-metadata # CVE # CloudSecurity # DataBreach # Phishing