Threats Tagged 'cve-2026-71211'
View all threats tagged with 'cve-2026-71211'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-71211'
Click on any threat for detailed analysis and mitigation recommendations
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no… (CVE-2026-71211)CVE-2026-71211 0 MLflow's AI Gateway has a vulnerability where the auth_config.api_base value used to create a gateway secret is accepted without validation of scheme, host, or IP range. This value is stored verbatim and later used by the gateway proxy endpoint to issue HTTP requests, potentially allowing SSRF attacks. The existing SSRF protections are not applied in this code path. Additionally, the CreateGatewaySecret action requires only basic authentication, allowing any authenticated user, including read-only accounts, to exploit this issue and potentially access internal addresses such as cloud metadata services. Join the discussion | GCVE Database | 08/05/2026, 09:31:18 UTC Added: 08/10/2026, 15:40:01 UTC |
Showing 1 to 1 of 1 result