DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

MLflow 2.x: Actively Exploited (CVE-2026-64849), Fixed Only in 3.15 — and Never Declared End of Life

CISA added MLflow’s CVSS 9.3 SSRF (CVE-2026-64849) to the KEV catalog on August 19, 2026 — federal deadline September 2. The fix exists only in 3.15.0; MLflow 2.x got no backport and was never declared end of life. Verified dates and the upgrade path.

MLflow 2.x is end of life — nobody announced it

Line First release Status Your move
MLflow 3.x 2025-06-10 Active — all fixes land here Be on 3.15.0 or later. Anything earlier in 3.x is vulnerable to CVE-2026-64849.
MLflow 2.x 2022-11-15 De facto EOL — no release since 2.22.5 Migrate to 3.15.0+. No patch exists for 2.x and none is coming.
MLflow 1.x 2019-06-04 EOL — last release 2023-04-05 Same, with a longer path.

What's covered

  • Key Dates at a Glance
  • What the vulnerability actually is
  • MLflow 2.x is end of life — nobody announced it
  • The pattern: third AI infrastructure tool on KEV in six weeks
  • What to do this week

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-mlflow-2-eol

Top comments (0)