Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2399
  • PyPI/bentoml
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2398
  • PyPI/bentoml
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2089
  • PyPI/bentoml
See record for full details 08 Jul
  • No fix available
  • Severity - 7.8 (High)
PYSEC-2026-1218
  • PyPI/bentoml
BentoML has a Path Traversal via Bentofile Configuration 07 Jul
  • Fix available
  • Severity - 7.4 (High)
PYSEC-2026-1219
  • PyPI/bentoml
BentoML Denial of Service (DoS) via Multipart Boundary 07 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-296
  • PyPI/bentoml
Insecure deserialization in BentoML 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-297
  • PyPI/bentoml
BentoML SSRF Vulnerability in File Upload Processing 29 Jun
  • Fix available
  • Severity - 9.9 (Critical)
PYSEC-2026-294
  • PyPI/bentoml
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-295
  • PyPI/bentoml
BentoML deserialization vulnerability 29 Jun
  • No fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-190
  • PyPI/bentoml
See record for full details 27 May
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-189
  • PyPI/bentoml
See record for full details 27 May
  • Fix available
  • Severity - 8.8 (High)
GHSA-w2pm-x38x-jp44
  • PyPI/bentoml
Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043) 11 May
  • Fix available
  • Severity - 8.8 (High)
GHSA-78f9-r8mh-4xm2
  • PyPI/bentoml
BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043) 11 May
  • Fix available
  • Severity - 8.8 (High)
GHSA-mcfx-4vc6-qgxv
  • PyPI/bentoml
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context 07 May
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-159
  • PyPI/bentoml
See record for full details 06 Apr
  • Fix available
  • Severity - 9.6 (Critical)
PYSEC-2026-158
  • PyPI/bentoml
See record for full details 06 Apr
  • Fix available
  • Severity - 7.8 (High)