CVE-2026-44345
- EPSS 0.32%
- Veröffentlicht 27.05.2026 17:24:18
- Zuletzt bearbeitet 02.06.2026 13:59:48
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 interpolates docker.base_image raw with no escaping, ...
CVE-2026-44346
- EPSS 0.32%
- Veröffentlicht 27.05.2026 17:22:47
- Zuletzt bearbeitet 02.06.2026 13:48:02
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].name produces unquoted RUN directives in the BentoML...
CVE-2026-40610
- EPSS 0.28%
- Veröffentlicht 22.05.2026 19:47:51
- Zuletzt bearbeitet 29.05.2026 18:53:06
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referen...
CVE-2026-35044
- EPSS 0.39%
- Veröffentlicht 06.04.2026 17:13:43
- Zuletzt bearbeitet 10.04.2026 18:31:47
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed...
CVE-2026-35043
- EPSS 0.32%
- Veröffentlicht 06.04.2026 17:10:24
- Zuletzt bearbeitet 10.04.2026 18:54:17
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 16...
CVE-2026-33744
- EPSS 0.26%
- Veröffentlicht 27.03.2026 01:16:21
- Zuletzt bearbeitet 01.04.2026 15:00:48
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packages` field in `bentofile.yaml` accepts arbitrary strings that are interpolated directly into Dockerfil...
CVE-2026-27905
- EPSS 0.26%
- Veröffentlicht 03.03.2026 22:45:40
- Zuletzt bearbeitet 05.03.2026 21:04:51
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink...
CVE-2026-24123
- EPSS 0.44%
- Veröffentlicht 26.01.2026 22:14:39
- Zuletzt bearbeitet 03.02.2026 15:07:55
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentofile.yaml` configuration allows path traversal attacks through multiple file path fields (`description...
CVE-2025-54381
- EPSS 11.11%
- Veröffentlicht 29.07.2025 22:11:24
- Zuletzt bearbeitet 05.08.2025 15:41:26
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers t...
CVE-2025-32375
- EPSS 43.81%
- Veröffentlicht 09.04.2025 15:30:03
- Zuletzt bearbeitet 22.04.2025 16:52:36
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST reques...