Skip to content
BentoMLGHSA-hvj5-mvw9-93j3

Insecure deserialization in BentoML

Critical9.8CVE-2024-2912 · Published Apr 16, 2024 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
bentoml
PyPI
< 1.2.51.2.5
Details and references

An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application. The vulnerability is triggered when a serialized object, crafted to execute OS commands upon deserialization, is sent to any valid BentoML endpoint. This issue poses a significant security risk, enabling attackers to compromise the server and potentially gain unauthorized access or control.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1188
Also known as
CVE-2024-2912, PYSEC-2026-296

More BentoML advisories

All BentoML
DateAdvisory
Mar 202025BentoML Open Redirect vulnerability
GHSA-564p-rx2q-4c8vMedium6.1no fix yet
Mar 202025BentoML vulnerable to Uncontrolled Resource Consumption
GHSA-hh3j-9m59-p8vcHigh7.5no fix yet
Mar 202025BentoML deserialization vulnerability
CVE-2024-9070Critical9.8no fix yet
Mar 202025BentoML Denial of Service (DoS) via Multipart Boundary
CVE-2024-9056High7.5no fix yet
Apr 42025BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-27520Critical9.8fixed in 1.4.3
Apr 92025BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-32375Critical9.8fixed in 1.4.8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.