Executive brief
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
Affected products
- PyPI mlflow
Junglewise Threat Intelligence
CVE-2025-14279 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: mlflow (PyPI). Vendors: PyPI.
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation