PT-2026-1734 · Databricks · Mlflow

Published

2026-01-12

·

Updated

2026-04-19

·

CVE-2025-14279

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MLFlow versions up to and including 3.4.0
Description MLFlow versions up to and including 3.4.0 are susceptible to DNS rebinding attacks because of missing Origin header validation within the MLFlow REST server. This allows malicious websites to circumvent Same-Origin Policy safeguards and perform unauthorized requests to REST endpoints. An attacker could query, update, and delete experiments through these endpoints, potentially resulting in data exfiltration, destruction, or manipulation. The REST server is affected.
Recommendations Update to version 3.5.0 or later.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2025-14279
CVE-2025-14279
GHSA-PGQP-8H46-6X4J

Affected Products

Mlflow