Database/AI/ML frameworks & serving
MLflow (REST API): DNS rebinding — no Origin header validation
CVSS 8.1CVE-2025-14279AI/ML frameworks & servingcurated
Impact
DNS rebinding — no Origin header validation
Who can reach it
Operator's browser visiting a malicious page while on the cluster network
What to do
Upgrade past 3.4.0
References
Related entries
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendCVE-2025-23318 · NVIDIA Triton (Python backend)High
- NVIDIA Triton (Python backend shared memory): Out-of-bounds write in the Python backendCVE-2025-23319 · NVIDIA Triton (Python backend shared memory)High
- LibreChat: agent Actions have no destination restrictions by default, reaching internal services via SSRFCVE-2025-69222 · LibreChat (agent Actions feature, outbound request allowlist)High
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetCVE-2025-71342 · picklescanHigh
- JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated originCVE-2026-102831 · JupyterLab / Jupyter Notebook / JupyterLite (system-clipboard cell paste)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.