Server-Side Request Forgery in BentoML Affects Internal Network Access
CVE-2026-78205

6.9MEDIUM

Key Information:

Vendor

Bentoml

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78205?

BentoML's security mechanism, designed to restrict outbound connections, inadequately handles requests to the RFC 6598 shared address space (100.64.0.0/10). This oversight allows attackers to exploit multipart file uploads or JSON requests in versions 1.4.19 through 1.4.39, enabling them to initiate outbound requests to internal resources on CGNAT networks. This vulnerability stems from a partial mitigation of a prior issue, heightening the risk on affected systems.

Affected Version(s)

BentoML 1.4.19 <= 1.4.39

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.