MLflow validated the URL, then followed a redirect and looked it up again — scanning began within hours
2026-08-19AI
CVE-2026-64849 is an unauthenticated SSRF in MLflow's webhook test endpoint, CVSS 9.3, fixed in 3.15.0. The check on the destination was real; it just was not pinned, so a redirect or a second DNS answer walked straight past it into cloud metadata. watchTowr saw exploitation attempts the same day the CVE was assigned.