CVE-2026-27905·Python vulnerability
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, not the symlink's target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem. This vulnerability is fixed in 1.4.36.
- Severity
- high
- Software
- Python
- Fixed in
- 1.4.36
- Published
- 2026-03-03
Affected versions
Until: 1.4.36
Fixed in: 1.4.36
How to fix this CVE
Upgrade BentoML to version 1.4.36 or later to patch a critical symlink validation bypass in the tar extraction function. The vulnerability allows attackers to write arbitrary files to the host filesystem through maliciously crafted bento/model archives. Immediately update Python and all BentoML dependencies to the patched version and redeploy affected services.
sudo dnf update python3-bentomlDefensia detects this vulnerability
How to check if you are affected
- Run 'python3 -m pip show bentoml' to display the installed BentoML version and verify if it is earlier than 1.4.36
- Check for bento/model tar files in your application's model repository with 'find /path/to/models -name '*.bento' -o -name '*.tar' | head -20'
- Search application logs for tar extraction errors or symlink-related warnings with 'grep -i 'symlink\|extract\|tarfile' /var/log/application.log | grep -i error'
- After patching, run 'python3 -m pip show bentoml' again and confirm the version is 1.4.36 or higher
FAQ
What is CVE-2026-27905?
This vulnerability exists in BentoML's tar extraction function, which fails to validate symlink targets during archive decompression. An attacker can craft a malicious bento package containing a symlink pointing outside the intended directory, then write arbitrary files through that symlink to compromise the host system.
Is CVE-2026-27905 being actively exploited?
No, there are currently no confirmed reports of active exploitation in the wild, and no public exploits are available. However, the high severity rating (CVSS 7.8) means organizations should prioritize patching.
What versions of Python are affected by CVE-2026-27905?
All versions of BentoML prior to 1.4.36 are vulnerable. The vulnerability affects any deployment using BentoML to load or extract model archives from untrusted sources.
How do I check if my server is vulnerable to CVE-2026-27905?
Run 'python3 -m pip show bentoml' and check the Version field. If it is less than 1.4.36, your installation is vulnerable to this symlink traversal flaw.
Does Defensia detect CVE-2026-27905?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If BentoML is installed on a monitored server, CVE-2026-27905 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-27905. Free for 1 server.
Get started free