← العودة للجدول
CVE-2026-4035
CVE-2026-4035 — GHSA: A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of...
📅 2026-06-03
🔴 Critical 🔥 No GHSA AI Attack Cloud CVSS 9.1 🎯 EPSS 0.28%

📋 الوصف الكامل

A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server'

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-4035

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←