Skip to content
BentoMLGHSA-9g44-gwvm-hc44

BentoML deserialization vulnerability

Critical9.8CVE-2024-9070 · Published Mar 20, 2025 · updated Jun 29, 2026

A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the server, causing severe harm. The vulnerability is triggered when the args-number parameter is greater than 1, leading to automatic deserialization and arbitrary code execution.

GitHub advisory

Affected versions

PackageAffectedFixed in
bentoml
PyPI
<= 1.4.5No fix yet
Details and references

More BentoML advisories

All BentoML
Advisory
BentoML SSRF Vulnerability in File Upload Processing
Critical9.9Jul 29, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 9, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 4, 2025
BentoML Denial of Service (DoS) via Multipart Boundary
High7.5Mar 20, 2025
BentoML Open Redirect vulnerability
Medium6.1Mar 20, 2025
BentoML vulnerable to Uncontrolled Resource Consumption
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.