CVE-2026-35043·Python vulnerability
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates system_packages directly into a shell command using an f-string without any quoting. The generated script is uploaded to BentoCloud as setup.sh and executed on the cloud build infrastructure during deployment, making this a remote code execution on the CI/CD tier. This vulnerability is fixed in 1.4.38.
- Severity
- high
- Software
- Python
- Fixed in
- 1.4.38
- Published
- 2026-04-06
Affected versions
Until: 1.4.38
Fixed in: 1.4.38
How to fix this CVE
Upgrade BentoML to version 1.4.38 or later to patch a critical shell command injection vulnerability in the cloud deployment module. This vulnerability allows arbitrary code execution during CI/CD pipeline execution when deploying models to BentoCloud. Organizations using BentoML for cloud deployments should prioritize this update immediately.
sudo dnf update python3-bentomlDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check installed BentoML version by running: python3 -c "import bentoml; print(bentoml.__version__)"
- Step 2: Verify if BentoML cloud deployment features are in use by checking for bentoml.cloud imports or bento.yaml cloud configuration in your project
- Step 3: Search deployment logs in BentoCloud for suspicious shell command patterns or unexpected package installations in setup.sh execution logs
- Step 4: Confirm the fix by upgrading to version 1.4.38+ and re-running: python3 -c "import bentoml; print(bentoml.__version__)" to verify the new version is active
FAQ
What is CVE-2026-35043?
CVE-2026-35043 is a shell command injection vulnerability in BentoML's cloud deployment module where system package names are interpolated directly into shell commands without proper escaping, allowing arbitrary code execution during model deployment to BentoCloud.
Is CVE-2026-35043 being actively exploited?
There is no evidence of active exploitation in the wild, and no public exploits are currently available. However, the attack surface is limited to organizations actively deploying models via BentoCloud.
What versions of BentoML are affected by CVE-2026-35043?
All versions of BentoML prior to 1.4.38 are affected. The vulnerability exists in the cloud deployment path (src/bentoml/_internal/cloud/deployment.py) and requires an upgrade to 1.4.38 or later.
How do I check if my server is vulnerable to CVE-2026-35043?
Run: python3 -c "import bentoml; print(bentoml.__version__)" and compare the version against 1.4.38. If your version is lower than 1.4.38 and you use BentoML cloud deployments, you are vulnerable.
Does Defensia detect CVE-2026-35043?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If BentoML is installed on a monitored server, CVE-2026-35043 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-35043. Free for 1 server.
Get started free