İçeriğe atla
Noroxi

bentoml kayıtları

bentoml üreticisine ait 13 yayımlanmış kayıt.

Tüm kayıtlar

13 kayıt
  • CVE-2025-32375
    55Planlayın

    Insecure Deserialization leads to RCE in BentoML's runner server

    KritikCVSS 9,8SilahlaştırılmışEPSS %52

    bentoml · bentoml9 Nis 2025

  • CVE-2025-27520
    51Planlayın

    BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

    KritikCVSS 9,8SilahlaştırılmışEPSS %41

    bentoml · bentoml4 Nis 2025

  • CVE-2025-54381
    44Planlayın

    BentoML is Vulnerable to an SSRF Attack Through File Upload Processing

    KritikCVSS 9,9Kavram kanıtıEPSS %16

    bentoml · bentoml29 Tem 2025

  • CVE-2024-2912
    40Planlayın

    Insecure Deserialization Leading to RCE in bentoml/bentoml

    KritikCVSS 10,0İstismar yokEPSS %2

    bentoml · bentoml/bentoml15 Nis 2024

  • CVE-2026-35044
    38İzleyin

    BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation

    KritikCVSS 9,6İstismar yokEPSS %0

    bentoml · bentoml6 Nis 2026

  • CVE-2026-44346
    35İzleyin

    BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml

    YüksekCVSS 8,8İstismar yokEPSS %0

    bentoml · bentoml27 May 2026

  • CVE-2026-44345
    35İzleyin

    BentoML: Dockerfile command injection via docker.base_image

    YüksekCVSS 8,8İstismar yokEPSS %0

    bentoml · bentoml27 May 2026

  • CVE-2026-27905
    34İzleyin

    BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

    YüksekCVSS 8,6İstismar yokEPSS %0

    bentoml · bentoml3 Mar 2026

  • CVE-2026-35043
    31İzleyin

    BentoML: command injection in cloud deployment setup script (deployment.py)

    YüksekCVSS 7,8İstismar yokEPSS %0

    bentoml · bentoml6 Nis 2026

  • CVE-2026-33744
    31İzleyin

    BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml

    YüksekCVSS 7,8İstismar yokEPSS %0

    bentoml · bentoml26 Mar 2026

  • CVE-2026-24123
    26İzleyin

    BentoML has a Path Traversal via Bentofile Configuration

    OrtaCVSS 6,5İstismar yokEPSS %0

    bentoml · bentoml26 Oca 2026

  • CVE-2026-40610
    22İzleyin

    BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

    OrtaCVSS 5,5İstismar yokEPSS %0

    bentoml · bentoml22 May 2026

  • bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection

    DüşükCVSS 1,9İstismar yokEPSS %2

    bentoml · openllm8 Tem 2026