bentoml kayıtları
bentoml üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %15,4
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %92,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-502 Deserialization of Untrusted Data2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-1188 Initialization of a Resource with an Insecure Default1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2025-32375Silahlaştırılmış | Insecure Deserialization leads to RCE in BentoML's runner serverbentoml · bentoml · CWE-502 | Kritik9,8 | — | %52,4 | 9 Nis 2025 |
51Planlayın | CVE-2025-27520Silahlaştırılmış | BentoML Allows Remote Code Execution (RCE) via Insecure Deserializationbentoml · bentoml · CWE-502 | Kritik9,8 | — | %40,6 | 4 Nis 2025 |
44Planlayın | CVE-2025-54381Kavram kanıtı | BentoML is Vulnerable to an SSRF Attack Through File Upload Processingbentoml · bentoml · CWE-918 | Kritik9,9 | — | %16,1 | 29 Tem 2025 |
40Planlayın | CVE-2024-2912İstismar yok | Insecure Deserialization Leading to RCE in bentoml/bentomlbentoml · bentoml/bentoml · CWE-1188 | Kritik10,0 | — | %1,5 | 15 Nis 2024 |
38İzleyin | CVE-2026-35044İstismar yok | BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generationbentoml · bentoml · CWE-1336 | Kritik9,6 | — | %0,5 | 6 Nis 2026 |
35İzleyin | CVE-2026-44346İstismar yok | BentoML: Dockerfile command injection via envs[*].name in bentofile.yamlbentoml · bentoml · CWE-78 | Yüksek8,8 | — | %0,5 | 27 May 2026 |
35İzleyin | CVE-2026-44345İstismar yok | BentoML: Dockerfile command injection via docker.base_imagebentoml · bentoml · CWE-78 | Yüksek8,8 | — | %0,5 | 27 May 2026 |
34İzleyin | CVE-2026-27905İstismar yok | BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extractionbentoml · bentoml · CWE-59 | Yüksek8,6 | — | %0,2 | 3 Mar 2026 |
31İzleyin | CVE-2026-35043İstismar yok | BentoML: command injection in cloud deployment setup script (deployment.py)bentoml · bentoml · CWE-78 | Yüksek7,8 | — | %0,3 | 6 Nis 2026 |
31İzleyin | CVE-2026-33744İstismar yok | BentoML has Dockerfile Command Injection via system_packages in bentofile.yamlbentoml · bentoml · CWE-94 | Yüksek7,8 | — | %0,2 | 26 Mar 2026 |
26İzleyin | CVE-2026-24123İstismar yok | BentoML has a Path Traversal via Bentofile Configurationbentoml · bentoml · CWE-22 | Orta6,5 | — | %0,5 | 26 Oca 2026 |
22İzleyin | CVE-2026-40610İstismar yok | BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build contextbentoml · bentoml · CWE-59 | Orta5,5 | — | %0,2 | 22 May 2026 |
8İzleyin | CVE-2026-15035İstismar yok | bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injectionbentoml · openllm · CWE-74 | Düşük1,9 | — | %2,2 | 8 Tem 2026 |
- CVE-2025-3237555Planlayın
Insecure Deserialization leads to RCE in BentoML's runner server
KritikCVSS 9,8SilahlaştırılmışEPSS %52bentoml · bentoml9 Nis 2025
- CVE-2025-2752051Planlayın
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
KritikCVSS 9,8SilahlaştırılmışEPSS %41bentoml · bentoml4 Nis 2025
- CVE-2025-5438144Planlayın
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
KritikCVSS 9,9Kavram kanıtıEPSS %16bentoml · bentoml29 Tem 2025
- CVE-2024-291240Planlayın
Insecure Deserialization Leading to RCE in bentoml/bentoml
KritikCVSS 10,0İstismar yokEPSS %2bentoml · bentoml/bentoml15 Nis 2024
- CVE-2026-3504438İzleyin
BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation
KritikCVSS 9,6İstismar yokEPSS %0bentoml · bentoml6 Nis 2026
- CVE-2026-4434635İzleyin
BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml
YüksekCVSS 8,8İstismar yokEPSS %0bentoml · bentoml27 May 2026
- CVE-2026-4434535İzleyin
BentoML: Dockerfile command injection via docker.base_image
YüksekCVSS 8,8İstismar yokEPSS %0bentoml · bentoml27 May 2026
- CVE-2026-2790534İzleyin
BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction
YüksekCVSS 8,6İstismar yokEPSS %0bentoml · bentoml3 Mar 2026
- CVE-2026-3504331İzleyin
BentoML: command injection in cloud deployment setup script (deployment.py)
YüksekCVSS 7,8İstismar yokEPSS %0bentoml · bentoml6 Nis 2026
- CVE-2026-3374431İzleyin
BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
YüksekCVSS 7,8İstismar yokEPSS %0bentoml · bentoml26 Mar 2026
- CVE-2026-2412326İzleyin
BentoML has a Path Traversal via Bentofile Configuration
OrtaCVSS 6,5İstismar yokEPSS %0bentoml · bentoml26 Oca 2026
- CVE-2026-4061022İzleyin
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
OrtaCVSS 5,5İstismar yokEPSS %0bentoml · bentoml22 May 2026
- CVE-2026-150358İzleyin
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
DüşükCVSS 1,9İstismar yokEPSS %2bentoml · openllm8 Tem 2026