CVE-2026-92568
5.4 MEDIUMpublic exploit availablePublished 2026-09-16 · Updated 2026-09-16
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-918
Public exploit & PoC references
All references
- https://github.com/mlrun/mlrun
- https://github.com/mlrun/mlrun/blob/6007f29e8b1ca976ea632e8714a312df50cb13e7/mlrun/utils/notifications/notification/webhook.py#L33-L94
- https://github.com/mlrun/mlrun/issues/10041
- https://www.vulncheck.com/advisories/mlrun-through-1.11.0-server-side-request-forgery-via-webhook
- https://github.com/mlrun/mlrun/issues/10041
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-10526
- MEDIUMCVE-2026-14939
- HIGHCVE-2026-15307PoC
- MEDIUMCVE-2026-1641
- MEDIUMCVE-2026-16536
- MEDIUMCVE-2026-16542
- MEDIUMCVE-2026-18774PoC
- MEDIUMCVE-2026-18775PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.