product of lfprojects

mlflow

2 thingsrelated by NVD
Severity
Exploited

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
Severity critical Exploited yes
mlflow/mlflow: mlflow/mlflow: Information disclosure and unauthorized data modification via unprotected tracing and assessment endpoints
CVE-2025-15381
Severity high