Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > MLflow
#MLflow

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Critical Vulnerability Threatens the Core of MLflow

6 December 2023  |  dark6  |  AI

Explore the profound implications of CVE-2023-43472, a critical vulnerability in MLflow, unraveling the threats to machine learning models and data integrity. Discover the urgent call to action within...

>> read more