High severity7.1NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-71211
CVE-2026-71211
Description
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mlflowPyPI | >= 3.13.0, <= 3.15.2 | — |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.