A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environm…
高危 CVSS 7.7
摘要
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to t…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/mlflow/mlflow/commit/4a3f2f720cb4f058c9e0c5b883e0acc9ab64a7f3 Patch
- https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233 Exploit
- https://access.redhat.com/security/cve/CVE-2026-4035
- https://bugzilla.redhat.com/show_bug.cgi?id=2484318
- https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233 Exploit
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4035.json
时间线
- nvd_ingest NVD