Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35044

32
FAUCET Score

OVERVIEW CVE-2026-35044 is a critical code injection vulnerability in BentoML versions prior to 1.4.38. The flaw exists in the Dockerfile generation function, which uses an unsandboxed Jinja2 template environment with unsafe extensions enabled. When a user imports a malicious bento archive and executes the containerize command, arbitrary Python code embedded in the dockerfile template executes directly on the host system with no container isolation. SEVERITY The vulnerability presents a critical risk with a CVSS score of 9.6. It requires no special privileges or authentication from the attacker, can be triggered via network means, and demands minimal interaction from the victim. The attack completely bypasses container security boundaries, granting the attacker the ability to compromise system confidentiality, integrity, and availability. The attack chain is straightforward, requiring only that a victim import a compromised bento archive. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the CISA Known Exploited Vulnerabilities catalog. The exploit concept is practical and requires no complex preconditions beyond social engineering to distribute a malicious bento archive. Community attention remains minimal, reflected in the low EPSS score of 0.00016, suggesting the vulnerability has not yet gained significant traction among threat actors or researchers.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.38CPE matchmatch criteria
cpe:2.3:a:bentoml:bentoml:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 36th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: bentomlFixed in: 1.4.38
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-v959-cwq9-7hr6high

BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation

Apr 3, 2026

References

github.com / bentoml/BentoML/security/advisories/GHSA-v959-cwq9-7hr6
ExploitVendor Advisory