
While creating ZeroDayBench, a member of our team discovered CVE-2025-14279, a high-severity DNS rebinding vulnerability in the MLFlow REST server allowing full read/write access to a user’s endpoint w/o authentication. Read more on: https://huntr.com/bounties/ef478f72-2e4f-44dc-8055-fc06bef03108
Post summary
The text announces the discovery of a high‑severity DNS rebinding vulnerability (CVE‑2025‑14279) in the MLFlow REST server that permits unauthenticated read/write access; additional details are available via a Huntr bounty link.

