<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:04:54.782913+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00109</id>
    <title>bdu:2026-00109</title>
    <updated>2026-10-08T08:04:54.820012+00:00</updated>
    <content>bdu:2026-00109</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248716</id>
    <title>EUVD-2026-248716</title>
    <updated>2026-10-08T08:04:54.820049+00:00</updated>
    <content>EUVD-2026-248716</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54381</id>
    <title>fkie_cve-2025-54381</title>
    <updated>2026-10-08T08:04:54.820063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. The vulnerability stems from the multipart form data and JSON request handlers, which automatically download files from user-provided URLs without validating whether those URLs point to internal network addresses, cloud metadata endpoints, or other restricted resources. The documentation explicitly promotes this URL-based file upload feature, making it an intended design that exposes all deployed services to SSRF attacks by default. Version 1.4.19 contains a patch for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54381"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mrmq-3q62-6cc8</id>
    <title>GHSA-mrmq-3q62-6cc8 — BentoML SSRF Vulnerability in File Upload Processing</title>
    <updated>2026-10-08T08:04:54.820096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p>### Description</p>
<p>There's an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.</p>
<p>The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.</p>
<p>The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.</p>
<p>### Source - Sink Analysis</p>
<p>**Source:** User-controlled multipart form field values and JSON request bodies containing URLs</p>
<p>**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` parses…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mrmq-3q62-6cc8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-297</id>
    <title>PYSEC-2026-297 — BentoML SSRF Vulnerability in File Upload Processing</title>
    <updated>2026-10-08T08:04:54.820147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p>### Description</p>
<p>There's an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.</p>
<p>The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.</p>
<p>The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.
 
### Source - Sink Analysis</p>
<p>**Source:** User-controlled multipart form field values and JSON request bodies containing URLs</p>
<p>**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` pars…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-297"/>
  </entry>
</feed>
