
CVE-2026-2393 A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a u… https://www.cve.org/CVERecord?id=CVE-2026-2393
Post summary
The post announces a Server‑Side Request Forgery flaw in MLflow before v3.9.0, naming the vulnerable function and affected versions, but offers no PoC, exploit, or patch details.


