CVE-2026-71211
published 2026-08-05CVE-2026-71211: MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.29%
19.1th percentile
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | 3.13.0 – 3.15.2 | — |
| mlflow | mlflow | <= 3.14.0 | — |
| rhoai | odh-core-bff-rhel9 | — | — |
| rhoai | odh-dashboard-operator-rhel9 | — | — |
| rhoai | odh-dashboard-rhel9 | — | — |
| rhoai | odh-data-science-pipelines-operator-controller-rhel9 | — | — |
| rhoai | odh-eval-hub-rhel9 | — | — |
| rhoai | odh-ml-pipelines-api-server-v2-rhel9 | — | — |
| rhoai | odh-ml-pipelines-driver-rhel9 | — | — |
| rhoai | odh-ml-pipelines-launcher-rhel9 | — | — |
| rhoai | odh-ml-pipelines-persistenceagent-v2-rhel9 | — | — |
| rhoai | odh-ml-pipelines-scheduledworkflow-v2-rhel9 | — | — |
| rhoai | odh-mlflow-operator-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-mod-arch-agent-ops-rhel9 | — | — |
| rhoai | odh-mod-arch-automl-rhel9 | — | — |
| rhoai | odh-mod-arch-autorag-rhel9 | — | — |
| rhoai | odh-mod-arch-eval-hub-rhel9 | — | — |
| rhoai | odh-mod-arch-gen-ai-rhel9 | — | — |
| rhoai | odh-mod-arch-maas-rhel9 | — | — |
| rhoai | odh-mod-arch-mlflow-rhel9 | — | — |
| rhoai | odh-mod-arch-model-registry-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
ghsa7.7HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MLflow AI Gateway permits SSRF through an unvalidated api_base
ghsa·2026-08-05·CVSS 7.7
CVE-2026-71211 [HIGH] CWE-918 MLflow AI Gateway permits SSRF through an unvalidated api_base
MLflow AI Gateway permits SSRF through an unvalidated api_base
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metadata IPs), is never invoked anywhere in this gateway secret/proxy code path. The CreateGatewaySecret action additionally has no entry in the permission-validator map, so it requires only basic authentication rather than any specific scope
GHSA
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value
ghsa_unreviewed·2026-08-05·CVSS 7.7
CVE-2026-71211 [HIGH] CWE-918 MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metadata IPs), is never invoked anywhere in this gateway secret/proxy code path. The CreateGatewaySecret action additionally has no entry in the permission-validator map, so it requires only basic authentication rather than any specific scope, meaning any authenticated user — including read-only accounts
Red Hat
mlflow: MLflow: Server-Side Request Forgery via unvalidated AI Gateway secret allows information disclosure
vendor_redhat·2026-08-05·CVSS 7.1
CVE-2026-71211 [HIGH] CWE-918 mlflow: MLflow: Server-Side Request Forgery via unvalidated AI Gateway secret allows information disclosure
mlflow: MLflow: Server-Side Request Forgery via unvalidated AI Gateway secret allows information disclosure
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body.
A flaw was found in MLflow's AI Gateway where an unvalidated `api_base` value in a gateway secret could lead to a Server-Side Request Forgery (SSRF) vulnerability. An authenticated user, even with read-only privileges, can create a secret with an internal network address. This
No detection rules found.
No public exploits indexed.
2026-08-05
Published