Server-Side Request Forgery in BentoML Affects Internal Network Access
CVE-2026-78205
6.9MEDIUM
What is CVE-2026-78205?
BentoML's security mechanism, designed to restrict outbound connections, inadequately handles requests to the RFC 6598 shared address space (100.64.0.0/10). This oversight allows attackers to exploit multipart file uploads or JSON requests in versions 1.4.19 through 1.4.39, enabling them to initiate outbound requests to internal resources on CGNAT networks. This vulnerability stems from a partial mitigation of a prior issue, heightening the risk on affected systems.
Affected Version(s)
BentoML 1.4.19 <= 1.4.39
