CVE-2026-64849
MLflow Webhooks SSRF to Internal Services
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An open-source AI engineering platform has a vulnerability where an unauthenticated request to its webhook test endpoint can be redirected to internal or cloud metadata services, potentially exposing sensitive information. This issue allows an attacker to reach internal services by exploiting improper URL validation af