{"data":{"ecosystem":"pypi","name":"bentoml","url":"https://aisecwatch.com/packages/pypi/bentoml","latestVersion":"1.4.39","firstReleaseAt":"2019-01-15T21:43:46.512Z","repository":"https://github.com/bentoml/bentoml","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["filesystem","http"],"fromDependencies":["pypi:aiohttp","pypi:httpx","pypi:pathspec"]},"dependencies":[{"ecosystem":"pypi","name":"bentoml-unsloth","versionSpec":">=0.1.0","scope":"extra:unsloth"},{"ecosystem":"pypi","name":"a2wsgi","versionSpec":">=1.10.7","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp-asgi-connector","versionSpec":">=1.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"aiosqlite","versionSpec":">=0.20.0","scope":"runtime"},{"ecosystem":"pypi","name":"attrs","versionSpec":">=22.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"cattrs","versionSpec":"<23.2.0,>=22.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"click","versionSpec":">=7.0","scope":"runtime"},{"ecosystem":"pypi","name":"click-option-group","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"cloudpickle","versionSpec":">=2.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"fsspec","versionSpec":">=2025.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"grpcio","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"grpcio-channelz","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"grpcio-health-checking","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"grpcio-reflection","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"httpx","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"httpx-ws","versionSpec":">=0.6.0","scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":">=3.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"kantoku","versionSpec":">=0.18.3","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"nvidia-ml-py","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-api","versionSpec":"~=1.20","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-exporter-jaeger","versionSpec":"~=1.20","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp","versionSpec":"~=1.20","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp-proto-grpc","versionSpec":"~=1.20","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp-proto-http","versionSpec":"~=1.20","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-exporter-zipkin","versionSpec":"~=1.20","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-instrumentation","versionSpec":"~=0.41b0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-instrumentation-aiohttp-client","versionSpec":"~=0.41b0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-instrumentation-asgi","versionSpec":"~=0.41b0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-instrumentation-grpc","versionSpec":"~=0.41b0","scope":"extra:all"},{"ecosystem":"pypi","name":"opentelemetry-sdk","versionSpec":"~=1.20","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-semantic-conventions","versionSpec":"~=0.41b0","scope":"runtime"},{"ecosystem":"pypi","name":"opentelemetry-util-http","versionSpec":"~=0.41b0","scope":"runtime"},{"ecosystem":"pypi","name":"packaging","versionSpec":">=22.0","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":">=1","scope":"extra:all"},{"ecosystem":"pypi","name":"pathspec","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"pip-requirements-parser","versionSpec":">=31.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"prometheus-client","versionSpec":">=0.10.0","scope":"runtime"},{"ecosystem":"pypi","name":"protobuf","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"psutil","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pyarrow","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3","scope":"runtime"},{"ecosystem":"pypi","name":"python-dateutil","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"python-json-logger","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":">=5.0","scope":"runtime"},{"ecosystem":"pypi","name":"rich","versionSpec":">=11.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"rich-toolkit","versionSpec":">=0.15.1","scope":"runtime"},{"ecosystem":"pypi","name":"s3fs","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"schema","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"simple-di","versionSpec":">=0.1.4","scope":"runtime"},{"ecosystem":"pypi","name":"starlette","versionSpec":">=0.24.0","scope":"runtime"},{"ecosystem":"pypi","name":"tomli","versionSpec":">=1.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"tomli-w","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"tritonclient","versionSpec":">=2.29.0","scope":"extra:triton"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":">=0.22.0","scope":"runtime"},{"ecosystem":"pypi","name":"watchfiles","versionSpec":">=0.15.0","scope":"runtime"}],"advisories":[{"id":"b170c921-960c-4cdc-9de0-82cfd4a13632","url":"https://aisecwatch.com/issues/b170c921-960c-4cdc-9de0-82cfd4a13632","cveId":"CVE-2026-44346","title":"GHSA-w2pm-x38x-jp44: Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043)","headline":null,"severity":"high","publishedAt":"2026-05-11T14:27:37.000Z","affected":["bentoml@<= 1.4.38 (fixed: 1.4.39)"],"epssScore":0.00476,"matchedBy":"ecosystem"},{"id":"92358181-5eb3-440e-a206-c36b157cc235","url":"https://aisecwatch.com/issues/92358181-5eb3-440e-a206-c36b157cc235","cveId":"CVE-2026-44345","title":"GHSA-78f9-r8mh-4xm2: BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)","headline":null,"severity":"high","publishedAt":"2026-05-11T14:27:06.000Z","affected":["bentoml@<= 1.4.38 (fixed: 1.4.39)"],"epssScore":0.00476,"matchedBy":"ecosystem"},{"id":"adcb521f-8a86-47a7-8cbe-59d6f4dc71be","url":"https://aisecwatch.com/issues/adcb521f-8a86-47a7-8cbe-59d6f4dc71be","cveId":"CVE-2026-40610","title":"GHSA-mcfx-4vc6-qgxv: BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context","headline":null,"severity":"medium","publishedAt":"2026-05-07T16:39:47.000Z","affected":["bentoml@<= 1.4.38 (fixed: 1.4.39)"],"epssScore":0.002,"matchedBy":"ecosystem"},{"id":"39cfe980-4f1f-47e4-af5c-06ae339826bc","url":"https://aisecwatch.com/issues/39cfe980-4f1f-47e4-af5c-06ae339826bc","cveId":"CVE-2026-35044","title":"GHSA-v959-cwq9-7hr6: BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation","headline":null,"severity":"high","publishedAt":"2026-04-03T23:14:15.000Z","affected":["bentoml@<= 1.4.37 (fixed: 1.4.38)"],"epssScore":0.0048,"matchedBy":"ecosystem"},{"id":"86acd869-57a4-4b47-9919-0ecb2f365eb6","url":"https://aisecwatch.com/issues/86acd869-57a4-4b47-9919-0ecb2f365eb6","cveId":"CVE-2026-35043","title":"GHSA-fgv4-6jr3-jgfw: BentoML: Command Injection in cloud deployment setup script","headline":null,"severity":"high","publishedAt":"2026-04-03T22:03:22.000Z","affected":["bentoml@<= 1.4.37 (fixed: 1.4.38)"],"epssScore":0.00261,"matchedBy":"ecosystem"},{"id":"9da1ba88-0695-45c0-aae3-13f48f849de1","url":"https://aisecwatch.com/issues/9da1ba88-0695-45c0-aae3-13f48f849de1","cveId":"CVE-2026-33744","title":"GHSA-jfjg-vc52-wqvf: BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml","headline":null,"severity":"high","publishedAt":"2026-03-26T07:32:44.000Z","affected":["bentoml@<= 1.4.36 (fixed: 1.4.37)"],"epssScore":0.00249,"matchedBy":"ecosystem"},{"id":"ec919c62-1cd0-4b9b-ab0f-df1cbccb9b5e","url":"https://aisecwatch.com/issues/ec919c62-1cd0-4b9b-ab0f-df1cbccb9b5e","cveId":"CVE-2026-27905","title":"GHSA-m6w7-qv66-g3mf: BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction","headline":null,"severity":"high","publishedAt":"2026-03-03T17:46:47.000Z","affected":["bentoml@< 1.4.36 (fixed: 1.4.36)"],"epssScore":0.00215,"matchedBy":"ecosystem"},{"id":"a6f15166-325d-42ef-9763-85cff77243ce","url":"https://aisecwatch.com/issues/a6f15166-325d-42ef-9763-85cff77243ce","cveId":"CVE-2026-24123","title":"CVE-2026-24123: BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to…","headline":"BentoML path traversal in bentofile.yaml file path fields","severity":"high","publishedAt":"2026-01-27T04:16:08.460Z","affected":["bentoml@< 1.4.34 (fixed: 1.4.34)"],"epssScore":0.00498,"matchedBy":"ecosystem"},{"id":"d1d5e003-24b5-4c2b-8c75-e9d1f82b9680","url":"https://aisecwatch.com/issues/d1d5e003-24b5-4c2b-8c75-e9d1f82b9680","cveId":"CVE-2025-54381","title":"CVE-2025-54381: BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions…","headline":"BentoML server-side request forgery through file upload URL handling","severity":"critical","publishedAt":"2025-07-30T03:15:32.947Z","affected":["bentoml@>= 1.4.0, < 1.4.19 (fixed: 1.4.19)"],"epssScore":0.16082,"matchedBy":"ecosystem"},{"id":"988cdafd-9752-4d0d-aee9-8bce44dce1cb","url":"https://aisecwatch.com/issues/988cdafd-9752-4d0d-aee9-8bce44dce1cb","cveId":"CVE-2025-32375","title":"CVE-2025-32375: BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to…","headline":"BentoML insecure deserialization in runner server via crafted POST request","severity":"critical","publishedAt":"2025-04-09T20:15:25.580Z","affected":["bentoml@>= 1.0.0a1, < 1.4.8 (fixed: 1.4.8)"],"epssScore":0.52415,"matchedBy":"ecosystem"},{"id":"dbbcb1b5-d0bd-4baa-aef2-cfc20bf086bf","url":"https://aisecwatch.com/issues/dbbcb1b5-d0bd-4baa-aef2-cfc20bf086bf","cveId":"CVE-2025-27520","title":"CVE-2025-27520: BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote…","headline":"BentoML remote code execution through insecure deserialization","severity":"critical","publishedAt":"2025-04-04T19:15:47.927Z","affected":["bentoml@>= 1.3.4, < 1.4.3 (fixed: 1.4.3)"],"epssScore":0.4062,"matchedBy":"ecosystem"},{"id":"5ef78ba3-fa78-4be9-af81-8f66d587d668","url":"https://aisecwatch.com/issues/5ef78ba3-fa78-4be9-af81-8f66d587d668","cveId":"CVE-2024-9070","title":"CVE-2024-9070: A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting…","headline":"BentoML runner server deserialization flaw enabling arbitrary code execution","severity":"critical","publishedAt":"2025-03-20T14:15:46.570Z","affected":["bentoml@<= 1.4.5"],"epssScore":0.00931,"matchedBy":"ecosystem"},{"id":"75abbaad-61d5-4a0f-b40f-4a45167bd02b","url":"https://aisecwatch.com/issues/75abbaad-61d5-4a0f-b40f-4a45167bd02b","cveId":"CVE-2024-9056","title":"CVE-2024-9056: BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by…","headline":"BentoML denial of service through malformed multipart boundary in HTTP request","severity":"medium","publishedAt":"2025-03-20T14:15:46.453Z","affected":["bentoml@<= 1.4.5"],"epssScore":0.00711,"matchedBy":"ecosystem"},{"id":"1e895207-2487-4440-bf75-87b53725236f","url":"https://aisecwatch.com/issues/1e895207-2487-4440-bf75-87b53725236f","cveId":"CVE-2024-2912","title":"CVE-2024-2912: An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by…","headline":"BentoML insecure deserialization leading to remote code execution via POST","severity":"critical","publishedAt":"2024-04-16T04:15:11.427Z","affected":["bentoml@< 1.2.5 (fixed: 1.2.5)"],"epssScore":0.01509,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:54:20.600Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}