Skip to content
BentoMLGHSA-hh3j-9m59-p8vc

BentoML vulnerable to Uncontrolled Resource Consumption

High7.5Published Mar 20, 2025 · updated Apr 15, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
bentoml
PyPI
<= 1.3.9No fix yet
Details and references

In bentoml/bentoml version 1.3.9, the `/login` endpoint of the newly integrated Gradio app is vulnerable to a Denial of Service (DoS) attack. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400

More BentoML advisories

All BentoML
DateAdvisory
Mar 202025BentoML Open Redirect vulnerability
GHSA-564p-rx2q-4c8vMedium6.1no fix yet
Mar 202025BentoML deserialization vulnerability
CVE-2024-9070Critical9.8no fix yet
Mar 202025BentoML Denial of Service (DoS) via Multipart Boundary
CVE-2024-9056High7.5no fix yet
Apr 42025BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-27520Critical9.8fixed in 1.4.3
Apr 92025BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-32375Critical9.8fixed in 1.4.8
Jul 292025BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-54381Critical9.9fixed in 1.4.19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.