Executive brief
BentoML is an AI model serving platform that processes HTTP requests and handles file uploads. An attacker can bypass the server's safeguard against connecting to internal networks by using RFC 6598 shared address space (100.64.0.0/10), allowing unauthorized outbound requests to internal hosts on networks using Carrier-Grade NAT. This affects servers that process untrusted URLs from users.
Technical details
BentoML's make_safe_connect() function in _internal/utils/uri.py blocks private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopback (127.0.0.0/8), and link-local (169.254.0.0/16) addresses. However, it fails to block RFC 6598 shared address space (100.64.0.0/10, used in Carrier-Grade NAT deployments). An unauthenticated attacker can supply malicious URLs targeting this range through multipart file upload handling (MultipartSerde.ensure_file) or JSON request parsing (JSONSerde.parse_request), forcing the server to make outbound SSRF requests to internal CGNAT-networked hosts. This is an incomplete fix for the prior CVE-2025-54381. Patch availability is not confirmed in the advisory text.
Affected products
- BentoML BentoML 1.4.19 through 1.4.39
Timeline
- 2026-08-24: disclosed