Junglewise Threat Intelligence

CVE-2025-14279: PYSEC-2026-1656 - MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

CVE-2025-14279 · Severity: low · CVSS 3 · Published 2026-07-07

Technologies: mlflow (PyPI). Vendors: PyPI.

Executive brief

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

Affected products

  • PyPI mlflow

Related threats