216.73.217.22

CVE-2025-14279

· Published 12/01/2026 09:15 · Modified 13/01/2026 14:03

Labels: CVE-2025-14279 2026-01-12CVE-2025-14279CWE-346[email protected]

Essential information

Published
12/01/2026 09:15
Modified
13/01/2026 14:03
Author
Creator
CVSS
8.1 HIGH (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against REST endpoints. An attacker can query, update, and delete experiments via the affected endpoints, leading to potential data exfiltration, destruction, or manipulation. The issue is resolved in version 3.5.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mlflow / mlflow cpe:2.3:a:mlflow:mlflow:3.4.0:*:*:*:*:*:*:*
mlflow / mlflow cpe:2.3:a:mlflow:mlflow:<3.5.0:*:*:*:*:*:*:*

References