<Vulnerability name="CVE-2026-64849">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-17T21:16:10</PublicDate>
    <Bugzilla id="2517655" url="https://bugzilla.redhat.com/show_bug.cgi?id=2517655" xml:lang="en:us">
mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-918</CWE>
    <Details xml:lang="en:us" source="Mitre">
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates only the initial URL, but then follows unvalidated HTTP redirects, allowing the attacker to bypass security controls. Successful exploitation can lead to information disclosure, enabling access to internal or cloud metadata services and sensitive data.
    </Details>
    <Statement xml:lang="en:us">
This flaw is in MLflow Tracking Server webhook delivery. An attacker who can reach the MLflow API can abuse POST /api/2.0/mlflow/webhooks/{id}/test to trigger SSRF and read upstream response bodies. Upstream rates this against the default unauthenticated mlflow server (PR:N).

For OpenShift AI, the operator-managed odh-mlflow-rhel9 image is the primary exposure; the operator enables kubernetes-auth by default, so unauthenticated abuse applies only where MLflow is deployed without authentication. The other 19 RHOAI images embed the mlflow Python package as a client library and do not execute the vulnerable server webhook path in their default role concluding those 19 RHOAI images as Not Affected.

Impact is set to Important with PR:L reflecting typical authenticated RHOAI deployments.
    </Statement>
    <Mitigation xml:lang="en:us">
To reduce the attack surface for this vulnerability, restrict network access to the MLflow server. Implement firewall rules or network access controls to limit connectivity to the MLflow instance from untrusted networks. This operational control helps prevent unauthenticated attackers from reaching the vulnerable webhook test endpoint.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:openshift_ai:3.4::el9">
        <ProductName>Red Hat OpenShift AI 3.4</ProductName>
        <ReleaseDate>2026-08-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60520">RHSA-2026:60520</Advisory>
        <Package name="rhoai/odh-mlflow-rhel9">rhoai/odh-mlflow-rhel9:1787226790</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift_ai:3.5::el9">
        <ProductName>Red Hat OpenShift AI 3.5</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60367">RHSA-2026:60367</Advisory>
        <Package name="rhoai/odh-latency-predictor-prediction-rhel9">rhoai/odh-latency-predictor-prediction-rhel9:1786552271</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:openshift_ai:3.5::el9">
        <ProductName>Red Hat OpenShift AI 3.5</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60367">RHSA-2026:60367</Advisory>
        <Package name="rhoai/odh-latency-predictor-training-rhel9">rhoai/odh-latency-predictor-training-rhel9:1786552250</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-th06-cpu-torch210-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-th06-cuda130-torch210-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-th06-rocm64-torch291-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-training-cuda128-torch29-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-64849
https://nvd.nist.gov/vuln/detail/CVE-2026-64849
https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939
https://github.com/mlflow/mlflow/issues/24179
https://github.com/mlflow/mlflow/pull/24258
https://github.com/mlflow/mlflow/releases/tag/v3.15.0
https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
    </References>
    <CSAw>True</CSAw>
</Vulnerability>