CISA added MLflow’s CVSS 9.3 SSRF (CVE-2026-64849) to the KEV catalog on August 19, 2026 — federal deadline September 2. The fix exists only in 3.15.0; MLflow 2.x got no backport and was never declared end of life. Verified dates and the upgrade path.
MLflow 2.x is end of life — nobody announced it
| Line | First release | Status | Your move |
|---|---|---|---|
| MLflow 3.x | 2025-06-10 | Active — all fixes land here | Be on 3.15.0 or later. Anything earlier in 3.x is vulnerable to CVE-2026-64849. |
| MLflow 2.x | 2022-11-15 | De facto EOL — no release since 2.22.5 | Migrate to 3.15.0+. No patch exists for 2.x and none is coming. |
| MLflow 1.x | 2019-06-04 | EOL — last release 2023-04-05 | Same, with a longer path. |
What's covered
- Key Dates at a Glance
- What the vulnerability actually is
- MLflow 2.x is end of life — nobody announced it
- The pattern: third AI infrastructure tool on KEV in six weeks
- What to do this week
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-mlflow-2-eol
Top comments (0)