Description
MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery
Action: Install Patch
AI Analysis

Impact

MLRun versions up to and including 1.11.0 contain a server‑side request forgery flaw in the WebhookNotification handler. An authenticated user can inject a malicious webhook notification during a run; when the run finishes, the API server automatically executes the notification and makes arbitrary HTTP requests to any address reachable from within the cluster. By directing these requests to internal services, the Kubernetes API, or cloud metadata endpoints, an attacker can exfiltrate data or gain information about the environment.

Affected Systems

The vulnerability affects the MLRun platform provided by mlrun:mlrun. It is present in all releases up to version 1.11.0 and is resolved in later releases. Users running earlier releases in any cloud or on‑premises Kubernetes cluster are potentially exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires that the user is already authenticated to the MLRun API; however, once that condition is satisfied, no additional privileges are needed to initiate the SSRF.

Generated by OpenCVE AI on September 18, 2026 at 05:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MLRun installation to the latest release (v1.11.1 or newer) where the WebhookNotification SSRF is fixed.
  • If an upgrade cannot be performed immediately, restrict the webhook URL validation to allow only trusted, external endpoints, or disable webhook notifications for critical runs via configuration.
  • Implement cluster‑wide network policies or firewall rules that prevent outbound traffic from the MLRun API server to internal IP ranges, blocking unintended requests to internal services.

Generated by OpenCVE AI on September 18, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Mlrun
Mlrun mlrun
Vendors & Products Mlrun
Mlrun mlrun

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.
Title MLRun through 1.11.0 Server-Side Request Forgery via Webhook
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:41.536Z

Reserved: 2026-09-16T13:34:45.154Z

Link: CVE-2026-92568

cve-icon Vulnrichment

Updated: 2026-09-16T15:23:22.580Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:02.453

Modified: 2026-09-23T17:17:48.090

Link: CVE-2026-92568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)