Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
BentoML Open Redirect vulnerability
BentoML has a Path Traversal via Bentofile Configuration
BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
BentoML deserialization vulnerability
BentoML: Command Injection in cloud deployment setup script
BentoML vulnerable to Uncontrolled Resource Consumption
Insecure deserialization in BentoML
BentoML Denial of Service (DoS) via Multipart Boundary
Other Machine Learning projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for BentoML — without relying on volunteer maintainers.
Talk to an Expert →