Unauthenticated full-read SSRF in webhook delivery
A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.
Read case study// research archive
Case studies show the boundary, root cause, validation method, impact, and remediation. Working exploit material stays out of the public record.
A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.
Read case studySSRF, API-key exposure, and response forgery were validated in an AI SDK integration that accepted a caller-influenced provider endpoint.
Read case studyLMDeploy enabled Hugging Face remote code by default during model loading, removing the operator decision that peer inference systems expose as an explicit opt-in.
Read case study