PublicCVE

CVE-2025-52967

MEDIUM5.8SSRF

Description

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected products

Updated 35m ago · 8 sources