CVE-2024-9056High· 7.5▾ TwilightBentoML Denial of Service (DoS) via Multipart Boundary
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.7%
BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.
bentoml <= 1.4.5Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54381Critical· 9.9BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-27520Critical· 9.8BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2026-40610Medium· 5.5BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
CVE-2026-27905HighBentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-24123High· 7.4BentoML has a Path Traversal via Bentofile Configuration
CVE-2026-15035High· 7.8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the…