Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, CGNAT). In versions 1.4.19 through 1.4.39, an unauthenticated attacker can supply URLs pointing to that range via multipart file handling (MultipartSerde.ensure_file) or JSON request parsing (JSONSerde.parse_request), causing the server to make outbound requests to internal hosts on CGNAT networks (Server-Side Request Forgery). This is an incomplete fix for CVE-2025-54381. | |
| Title | BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC 6598 Shared Address Space | |
| First Time appeared |
Bentoml
Bentoml bentoml |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:bentoml:bentoml:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Bentoml
Bentoml bentoml |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T00:30:45.786Z
Reserved: 2026-08-23T23:45:12.185Z
Link: CVE-2026-78205
No data.
Status : Received
Published: 2026-08-24T01:16:57.823
Modified: 2026-08-24T01:16:57.823
Link: CVE-2026-78205
No data.
OpenCVE Enrichment
Updated: 2026-08-24T01:30:04Z