Server-Side-Request-Forgery
Unauthenticated MLflow Webhook SSRF (CVE-2026-64849) Exploited Within Hours to Steal Cloud Credentials
An unauthenticated SSRF in MLflow's webhook-test endpoint, CVE-2026-64849, lets attackers bypass an existing SSRF guard via HTTP redirects to reach cloud metadata services — and exploitation began within hours of the CVE going public.