Bug 2469196 (CVE-2026-2393)
| Summary: | CVE-2026-2393 mlflow: MLflow: Server-Side Request Forgery (SSRF) allows internal network access and data exfiltration. | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in MLflow. An authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by providing an unvalidated URL parameter to the `_create_webhook()` function. This allows the MLflow backend to be forced into sending HTTP requests to internal services, cloud metadata endpoints, or arbitrary external servers. The lack of input validation on the webhook URL enables this exploitation, potentially leading to cloud credential theft, internal network access, and data exfiltration.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-05-11 18:03:02 UTC
|