A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abused to get a remote code execution on the victim machine.
"https://github.com/pypa/advisory-database/blob/main/vulns/mlflow/PYSEC-2026-416.yaml"