CVE-2026-71211 | MLflow up to 3.14.0 AI Gateway handlers.py _create_gateway_secret auth_config.api_base server-side request forgery (EUVD-2026-53208)
A vulnerability, which was classified as critical, was found in MLflow up to 3.14.0. This affects the function _create_gateway_secret of the file mlflow/server/handlers.py of the component AI Gateway. Such manipulation of the argument auth_config.api_base leads to server-side request forgery.
This vulnerability is listed as CVE-2026-71211. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More