Server-Side Request Forgery in MLRun WebhookNotification Handler
CVE-2026-92568
5.3MEDIUM
What is CVE-2026-92568?
MLRun versions up to 1.11.0 are susceptible to a server-side request forgery vulnerability within the WebhookNotification handler. This allows authenticated users to send arbitrary HTTP requests via the API server to internal addresses. Attackers can exploit this vulnerability by submitting a malicious webhook notification that triggers when a run reaches its terminal state. Consequently, this could facilitate unauthorized access to internal services, Kubernetes APIs, or cloud metadata endpoints, posing significant security risks to the application and its infrastructure.
Affected Version(s)
mlrun 0 <= 1.11.0
