Skip to content
BentoMLGHSA-hw8j-hw49-752c

BentoML Denial of Service (DoS) via Multipart Boundary

High7.5CVE-2024-9056 · Published Mar 20, 2025 · updated Jul 7, 2026

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.

GitHub advisory

Affected versions

PackageAffectedFixed in
bentoml
PyPI
<= 1.4.5No fix yet
Details and references

More BentoML advisories

All BentoML
Advisory
BentoML SSRF Vulnerability in File Upload Processing
Critical9.9Jul 29, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 9, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 4, 2025
BentoML deserialization vulnerability
Critical9.8Mar 20, 2025
BentoML Open Redirect vulnerability
Medium6.1Mar 20, 2025
BentoML vulnerable to Uncontrolled Resource Consumption
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.