Server-Side Request Forgery in MLRun WebhookNotification Handler
CVE-2026-92568

5.3MEDIUM

Key Information:

Vendor

Mlrun

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92568?

MLRun versions up to 1.11.0 are susceptible to a server-side request forgery vulnerability within the WebhookNotification handler. This allows authenticated users to send arbitrary HTTP requests via the API server to internal addresses. Attackers can exploit this vulnerability by submitting a malicious webhook notification that triggers when a run reaches its terminal state. Consequently, this could facilitate unauthorized access to internal services, Kubernetes APIs, or cloud metadata endpoints, posing significant security risks to the application and its infrastructure.

Affected Version(s)

mlrun 0 <= 1.11.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.