Database/AI/ML frameworks & serving
BentoML 1.3.9 (bundled Gradio app, /login endpoint): The /login endpoint of the integrated Gradio app processes each
Impact
The /login endpoint of the integrated Gradio app processes each appended character in a malformed multipart boundary, consuming resources until the service is unavailable. No CVE was assigned to the BentoML advisory itself; the underlying Gradio issue is tracked as CVE-2024-8966. Effect on an operator is a model server that stops serving while still holding its GPU.
Who can reach it
Unauthenticated, no user interaction. Anything that can reach the BentoML serving port.
What to do
Upgrade BentoML past 1.3.9 and restart serving pods. Cap request size at the ingress in front of the endpoint as a durable mitigation for this whole class.
References
Related entries
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /create_projectCVE-2025-27770 · UpTrain dashboard backend (/create_project endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /add_promptsCVE-2025-27771 · UpTrain dashboard backend (/add_prompts endpoint)High
- UpTrain: authenticated remote code execution via the checks and metadata parameters on /new_runCVE-2025-27772 · UpTrain dashboard backend (/new_run endpoint)High
- joblib: Arbitrary code execution via `eval` on the `pre_dispatch` flag in `Parallel()`CVE-2022-21797 · joblibHigh
- Gradio: Lack of path filteringCVE-2023-34239 · GradioHigh
- jupyter-lsp: Unauthenticated file read/write through the LSP extensionCVE-2024-22415 · jupyter-lspHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.