<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:53:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00109</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00109</link>
      <description>bdu:2026-00109</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00109</guid>
    </item>
    <item>
      <title>EUVD-2026-248716</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248716</link>
      <description>EUVD-2026-248716</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248716</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54381</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54381</link>
      <description>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. The vulnerability stems from the multipart form data and JSON request handlers, which automatically download files from user-provided URLs without validating whether those URLs point to internal network addresses, cloud metadata endpoints, or other restricted resources. The documentation explicitly promotes this URL-based file upload feature, making it an intended design that exposes all deployed services to SSRF attacks by default. Version 1.4.19 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. The vulnerability stems from the multipart form data and JSON request handlers, which automatically download files from user-provided URLs without validating whether those URLs point to internal network addresses, cloud metadata endpoints, or other restricted resources. The documentation explicitly promotes this URL-based file upload feature, making it an intended design that exposes all deployed services to SSRF attacks by default. Version 1.4.19 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54381</guid>
    </item>
    <item>
      <title>GHSA-mrmq-3q62-6cc8 — BentoML SSRF Vulnerability in File Upload Processing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mrmq-3q62-6cc8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;There&amp;#39;s an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.&lt;/p&gt;
&lt;p&gt;The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.&lt;/p&gt;
&lt;p&gt;The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.&lt;/p&gt;
&lt;p&gt;### Source - Sink Analysis&lt;/p&gt;
&lt;p&gt;**Source:** User-controlled multipart form field values and JSON request bodies containing URLs&lt;/p&gt;
&lt;p&gt;**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` parses…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;There&amp;#39;s an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.&lt;/p&gt;
&lt;p&gt;The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.&lt;/p&gt;
&lt;p&gt;The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.&lt;/p&gt;
&lt;p&gt;### Source - Sink Analysis&lt;/p&gt;
&lt;p&gt;**Source:** User-controlled multipart form field values and JSON request bodies containing URLs&lt;/p&gt;
&lt;p&gt;**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` parses…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mrmq-3q62-6cc8</guid>
    </item>
    <item>
      <title>PYSEC-2026-297 — BentoML SSRF Vulnerability in File Upload Processing</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-297</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;There&amp;#39;s an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.&lt;/p&gt;
&lt;p&gt;The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.&lt;/p&gt;
&lt;p&gt;The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.
 
### Source - Sink Analysis&lt;/p&gt;
&lt;p&gt;**Source:** User-controlled multipart form field values and JSON request bodies containing URLs&lt;/p&gt;
&lt;p&gt;**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` pars…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;There&amp;#39;s an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.&lt;/p&gt;
&lt;p&gt;The framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.&lt;/p&gt;
&lt;p&gt;The documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.
 
### Source - Sink Analysis&lt;/p&gt;
&lt;p&gt;**Source:** User-controlled multipart form field values and JSON request bodies containing URLs&lt;/p&gt;
&lt;p&gt;**Call Chain - Path 1 (MultipartSerde - No Validation):**
1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  
2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request
3. `form = await request.form()` pars…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-297</guid>
    </item>
  </channel>
</rss>
