<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — MLflow</title><description>Actively exploited vulnerabilities affecting MLflow products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/mlflow.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-64849</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-64849</guid><description>This Server-Side Request Forgery (SSRF) flaw in MLflow allows an attacker to make the MLflow server issue requests on their behalf to internal network resources or cloud metadata services — such as AWS IMDSv1 or similar endpoints. The attacker can then read the response status and body, potentially harvesting cloud credentials, internal service data, or other sensitive information that should never be externally accessible. Organizations running MLflow in cloud or hybrid environments face elevated risk.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>MLflow</category><category>MLflow</category></item></channel></rss>