{"schema_version":1,"title":"bentoml (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in bentoml (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-27905, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/bentoml","json_url":"https://junglewise.ai/threats/technologies/bentoml.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/bentoml","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":8,"last_365_days":14},"latest":[{"cve":"CVE-2026-27905","cvss":4,"epss":0.0021,"slug":"cve-2026-27905-bentoml-vulnerable-to-arbitrary-file-write-via-symlink-path","title":"PYSEC-2026-2398 - BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:40.716464+00:00","url":"https://junglewise.ai/threats/cve-2026-27905-bentoml-vulnerable-to-arbitrary-file-write-via-symlink-path"},{"cve":"CVE-2026-15035","cvss":5.3,"epss":0.0222,"slug":"cve-2026-15035-bentoml-openllm-command-injection-in-model-repository-directory","title":"bentoml OpenLLM command injection in Model Repository Directory Name Handler","severity":"medium","exploited":false,"published_at":"2026-07-08T14:16:56.643+00:00","url":"https://junglewise.ai/threats/cve-2026-15035-bentoml-openllm-command-injection-in-model-repository-directory"},{"cve":"CVE-2026-24123","cvss":3.1,"epss":0.005,"slug":"cve-2026-24123-bentoml-has-a-path-traversal-via-bentofile-configuration","title":"PYSEC-2026-1218 - BentoML has a Path Traversal via Bentofile Configuration","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:20.232952+00:00","url":"https://junglewise.ai/threats/cve-2026-24123-bentoml-has-a-path-traversal-via-bentofile-configuration"},{"cve":"CVE-2024-9056","cvss":3,"epss":0.0071,"slug":"cve-2024-9056-bentoml-denial-of-service-dos-via-multipart-boundary","title":"PYSEC-2026-1219 - BentoML Denial of Service (DoS) via Multipart Boundary","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:57.864964+00:00","url":"https://junglewise.ai/threats/cve-2024-9056-bentoml-denial-of-service-dos-via-multipart-boundary"},{"cve":"CVE-2024-2912","cvss":3,"epss":0.0151,"slug":"cve-2024-2912-insecure-deserialization-in-bentoml","title":"PYSEC-2026-296 - Insecure deserialization in BentoML","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.465878+00:00","url":"https://junglewise.ai/threats/cve-2024-2912-insecure-deserialization-in-bentoml"},{"cve":"CVE-2025-54381","cvss":3.1,"epss":0.1477,"slug":"cve-2025-54381-bentoml-ssrf-vulnerability-in-file-upload-processing","title":"PYSEC-2026-297 - BentoML SSRF Vulnerability in File Upload Processing","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:37.216989+00:00","url":"https://junglewise.ai/threats/cve-2025-54381-bentoml-ssrf-vulnerability-in-file-upload-processing"},{"cve":"CVE-2025-27520","cvss":3.1,"epss":0.4062,"slug":"cve-2025-27520-bentoml-insecure-deserialization-remote-code-execution","title":"PYSEC-2026-294 - BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:35.81593+00:00","url":"https://junglewise.ai/threats/cve-2025-27520-bentoml-insecure-deserialization-remote-code-execution"},{"cve":"CVE-2024-9070","cvss":3,"epss":0.0093,"slug":"cve-2024-9070-bentoml-deserialization-vulnerability","title":"PYSEC-2026-295 - BentoML deserialization vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:34.505033+00:00","url":"https://junglewise.ai/threats/cve-2024-9070-bentoml-deserialization-vulnerability"},{"cve":"CVE-2026-44346","cvss":8.8,"epss":0.0048,"slug":"cve-2026-44346-bentoml-command-injection-in-dockerfile-generation-via-bentofile","title":"BentoML command injection in Dockerfile generation via bentofile.yaml","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.333+00:00","url":"https://junglewise.ai/threats/cve-2026-44346-bentoml-command-injection-in-dockerfile-generation-via-bentofile"},{"cve":"CVE-2026-44345","cvss":8.8,"epss":0.0048,"slug":"cve-2026-44345-bentoml-command-injection-in-dockerfile-base-image-template","title":"BentoML command injection in Dockerfile base_image template","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.2+00:00","url":"https://junglewise.ai/threats/cve-2026-44345-bentoml-command-injection-in-dockerfile-base-image-template"},{"cve":"CVE-2026-40610","cvss":5.5,"epss":0.002,"slug":"cve-2026-40610-bentoml-information-disclosure-via-symlink-traversal-in-build","title":"BentoML information disclosure via symlink traversal in build context","severity":"medium","exploited":false,"published_at":"2026-05-22T20:16:34.76+00:00","url":"https://junglewise.ai/threats/cve-2026-40610-bentoml-information-disclosure-via-symlink-traversal-in-build"},{"cve":"CVE-2026-35044","cvss":8.8,"epss":0.0048,"slug":"cve-2026-35044-bentoml-ssti-in-dockerfile-generation","title":"BentoML SSTI in Dockerfile generation","severity":"high","exploited":false,"published_at":"2026-04-03T23:14:15+00:00","url":"https://junglewise.ai/threats/cve-2026-35044-bentoml-ssti-in-dockerfile-generation"},{"cve":"CVE-2026-35043","cvss":7.8,"epss":0.0026,"slug":"cve-2026-35043-bentoml-command-injection-in-cloud-deployment-setup-script","title":"BentoML command injection in cloud deployment setup script","severity":"high","exploited":false,"published_at":"2026-04-03T22:03:22+00:00","url":"https://junglewise.ai/threats/cve-2026-35043-bentoml-command-injection-in-cloud-deployment-setup-script"},{"cve":"CVE-2026-33744","cvss":7.8,"epss":0.0025,"slug":"cve-2026-33744-bentoml-command-injection-in-bentofile-yaml-system-packages","title":"BentoML command injection in bentofile.yaml system_packages","severity":"high","exploited":false,"published_at":"2026-03-26T07:32:44+00:00","url":"https://junglewise.ai/threats/cve-2026-33744-bentoml-command-injection-in-bentofile-yaml-system-packages"},{"cve":"CVE-2025-32375","cvss":3.1,"epss":0.5242,"slug":"cve-2025-32375-bentoml-s-runner-server-vulnerable-to-remote-code-execution-rce","title":"PYSEC-2025-32 - BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an inse","severity":"low","exploited":false,"published_at":"2025-04-09T16:15:25+00:00","url":"https://junglewise.ai/threats/cve-2025-32375-bentoml-s-runner-server-vulnerable-to-remote-code-execution-rce"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"bentoml (PyPI)","slug":"bentoml","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.bentoml.com/","repo_url":"https://github.com/bentoml/BentoML","description":"A framework for building, serving, and deploying machine learning models.","url":"https://junglewise.ai/threats/technologies/bentoml"},"most_severe":[{"cve":"CVE-2026-44346","cvss":8.8,"epss":0.0048,"slug":"cve-2026-44346-bentoml-command-injection-in-dockerfile-generation-via-bentofile","title":"BentoML command injection in Dockerfile generation via bentofile.yaml","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.333+00:00","url":"https://junglewise.ai/threats/cve-2026-44346-bentoml-command-injection-in-dockerfile-generation-via-bentofile"},{"cve":"CVE-2026-44345","cvss":8.8,"epss":0.0048,"slug":"cve-2026-44345-bentoml-command-injection-in-dockerfile-base-image-template","title":"BentoML command injection in Dockerfile base_image template","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.2+00:00","url":"https://junglewise.ai/threats/cve-2026-44345-bentoml-command-injection-in-dockerfile-base-image-template"},{"cve":"CVE-2026-35044","cvss":8.8,"epss":0.0048,"slug":"cve-2026-35044-bentoml-ssti-in-dockerfile-generation","title":"BentoML SSTI in Dockerfile generation","severity":"high","exploited":false,"published_at":"2026-04-03T23:14:15+00:00","url":"https://junglewise.ai/threats/cve-2026-35044-bentoml-ssti-in-dockerfile-generation"},{"cve":"CVE-2026-35043","cvss":7.8,"epss":0.0026,"slug":"cve-2026-35043-bentoml-command-injection-in-cloud-deployment-setup-script","title":"BentoML command injection in cloud deployment setup script","severity":"high","exploited":false,"published_at":"2026-04-03T22:03:22+00:00","url":"https://junglewise.ai/threats/cve-2026-35043-bentoml-command-injection-in-cloud-deployment-setup-script"},{"cve":"CVE-2026-33744","cvss":7.8,"epss":0.0025,"slug":"cve-2026-33744-bentoml-command-injection-in-bentofile-yaml-system-packages","title":"BentoML command injection in bentofile.yaml system_packages","severity":"high","exploited":false,"published_at":"2026-03-26T07:32:44+00:00","url":"https://junglewise.ai/threats/cve-2026-33744-bentoml-command-injection-in-bentofile-yaml-system-packages"},{"cve":"CVE-2026-40610","cvss":5.5,"epss":0.002,"slug":"cve-2026-40610-bentoml-information-disclosure-via-symlink-traversal-in-build","title":"BentoML information disclosure via symlink traversal in build context","severity":"medium","exploited":false,"published_at":"2026-05-22T20:16:34.76+00:00","url":"https://junglewise.ai/threats/cve-2026-40610-bentoml-information-disclosure-via-symlink-traversal-in-build"},{"cve":"CVE-2026-15035","cvss":5.3,"epss":0.0222,"slug":"cve-2026-15035-bentoml-openllm-command-injection-in-model-repository-directory","title":"bentoml OpenLLM command injection in Model Repository Directory Name Handler","severity":"medium","exploited":false,"published_at":"2026-07-08T14:16:56.643+00:00","url":"https://junglewise.ai/threats/cve-2026-15035-bentoml-openllm-command-injection-in-model-repository-directory"},{"cve":"CVE-2026-27905","cvss":4,"epss":0.0021,"slug":"cve-2026-27905-bentoml-vulnerable-to-arbitrary-file-write-via-symlink-path","title":"PYSEC-2026-2398 - BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:40.716464+00:00","url":"https://junglewise.ai/threats/cve-2026-27905-bentoml-vulnerable-to-arbitrary-file-write-via-symlink-path"},{"cve":"CVE-2025-32375","cvss":3.1,"epss":0.5242,"slug":"cve-2025-32375-bentoml-s-runner-server-vulnerable-to-remote-code-execution-rce","title":"PYSEC-2025-32 - BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an inse","severity":"low","exploited":false,"published_at":"2025-04-09T16:15:25+00:00","url":"https://junglewise.ai/threats/cve-2025-32375-bentoml-s-runner-server-vulnerable-to-remote-code-execution-rce"},{"cve":"CVE-2025-27520","cvss":3.1,"epss":0.4062,"slug":"cve-2025-27520-bentoml-insecure-deserialization-remote-code-execution","title":"PYSEC-2026-294 - BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:35.81593+00:00","url":"https://junglewise.ai/threats/cve-2025-27520-bentoml-insecure-deserialization-remote-code-execution"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}