← Vulnerability feed

Vulnerability record · CVE-2025-32375 · published 9 April 2025

CVE-2025-32375: BentoML runner server insecure deserialization enables unauthenticated RCE

Bentoml · Bentoml

BentoML before 1.4.8 deserializes untrusted data in its runner server. By sending a crafted POST request with specific headers and parameters, an attacker can execute arbitrary code on the server. The flaw is fixed in 1.4.8.

9.8 CVSS 3.1 Critical EPSS 52% · top 1.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, and public exploit code plus high EPSS make this an urgent remote code execution risk.

What it is

BentoML before 1.4.8 deserializes untrusted data in its runner server. By sending a crafted POST request with specific headers and parameters, an attacker can execute arbitrary code on the server. The flaw is fixed in 1.4.8.

Impact

An unauthenticated attacker gains remote code execution on the BentoML runner server, leading to initial access and information disclosure.

Attack surface

Reachable over the network via a POST request to the runner server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is 0.52415 (98.9th percentile) and the vendor advisory is tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade BentoML to 1.4.8 or later immediately.
  • Restrict network access to BentoML runner servers to trusted clients only.
  • Place runner servers behind authentication and a reverse proxy where feasible.
  • Monitor for and block POST requests containing unexpected serialized payloads or headers.

Detection

  • Inspect BentoML runner server logs for anomalous POST requests with unusual headers or parameters.
  • Monitor for unexpected child processes or outbound connections spawned by the BentoML process.
  • Use network detection to flag serialized payload patterns in HTTP request bodies to runner endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-32375 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-54381Bentoml server-side request forgery (ssrf) vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file u…EPSS 15%9.8CVE-2025-27520Bentoml deserialization of untrusted data vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerabilit…EPSS 41%9.6CVE-2026-35044Bentoml vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation…EPSS 0.48%8.8CVE-2026-44345Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/con…EPSS 0.48%8.8CVE-2026-44346Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam…EPSS 0.48%8.6CVE-2026-27905Bentoml link following vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile(…EPSS 0.21%7.8CVE-2026-35043Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path…EPSS 0.26%7.8CVE-2026-33744Bentoml code injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packag…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-32375), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.