Denial of Service Vulnerability in BentoML by Compromised HTTP Requests
CVE-2024-9056

7.5HIGH

Key Information:

Vendor

Bentoml

Vendor
CVE Published:
20 March 2025

What is CVE-2024-9056?

BentoML version v1.3.4post1 is susceptible to a Denial of Service attack, allowing unauthorized users to exploit the vulnerability by appending additional characters to the multipart boundary in an HTTP request. This manipulation causes the server to consume excessive resources as it processes each appended character individually. As a result, the service becomes unable to respond to legitimate requests, rendering it unavailable to all users. Notably, this attack does not require any authentication or user interaction, thus posing a significant risk to the overall service availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

bentoml/bentoml <= unspecified

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.