{"api_version":"v1","generated_at":"2026-10-08T17:15:00+00:00","product":{"cve_count":12,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-bentoml-bentoml-d37d57bbb387","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"BentoML","next_cursor":null,"observations":[{"affected":"BentoML: 1.4.19 \u2264 1.4.39","affected_versions_present":true,"cve_id":"CVE-2026-78205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78205","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-24T19:02:28.061Z","patch_url":"","primary_source":"","published":"2026-08-24T00:30:45.786Z"},{"affected":"< 1.4.39","affected_versions_present":true,"cve_id":"CVE-2026-44345","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44345","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:00:32.386Z","patch_url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-78f9-r8mh-4xm2","primary_source":"","published":"2026-05-27T17:24:18.789Z"},{"affected":"< 1.4.39","affected_versions_present":true,"cve_id":"CVE-2026-44346","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44346","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T15:09:40.051Z","patch_url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-w2pm-x38x-jp44","primary_source":"","published":"2026-05-27T17:22:47.101Z"},{"affected":"BentoML: < 1.4.39","affected_versions_present":true,"cve_id":"CVE-2026-40610","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40610","fixed":"1.4.39.","last_modified":"2026-05-26T15:33:25.507Z","patch_url":"https://github.com/bentoml/BentoML/commit/5fb7cd41f92e2a56b45391284cf15b9ac9963a1f","primary_source":"","published":"2026-05-22T19:47:51.660Z"},{"affected":"< 1.4.38","affected_versions_present":true,"cve_id":"CVE-2026-35044","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35044","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-06T18:49:59.815Z","patch_url":"","primary_source":"","published":"2026-04-06T17:13:43.133Z"},{"affected":"< 1.4.38","affected_versions_present":true,"cve_id":"CVE-2026-35043","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35043","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-07T14:09:07.570Z","patch_url":"","primary_source":"","published":"2026-04-06T17:10:24.466Z"},{"affected":"BentoML: < 1.4.37","affected_versions_present":true,"cve_id":"CVE-2026-33744","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33744","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T20:01:40.600Z","patch_url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-jfjg-vc52-wqvf","primary_source":"","published":"2026-03-27T00:45:08.108Z"},{"affected":"BentoML: < 1.4.36","affected_versions_present":true,"cve_id":"CVE-2026-27905","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27905","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-04T21:23:39.612Z","patch_url":"https://github.com/bentoml/BentoML/commit/4e0eb007765ac04c7924220d643f264715cc9670","primary_source":"","published":"2026-03-03T22:45:40.434Z"},{"affected":"< 1.4.34","affected_versions_present":true,"cve_id":"CVE-2026-24123","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24123","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-27T21:37:03.727Z","patch_url":"https://github.com/bentoml/BentoML/commit/84d08cfeb40c5f2ce71b3d3444bbaa0fb16b5ca4","primary_source":"","published":"2026-01-26T22:14:39.709Z"},{"affected":">= 1.4.0, < 1.4.19","affected_versions_present":true,"cve_id":"CVE-2025-54381","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54381","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-30T15:07:10.836Z","patch_url":"https://github.com/bentoml/BentoML/commit/534c3584621da4ab954bdc3d814cc66b95ae5fb8","primary_source":"","published":"2025-07-29T22:11:24.407Z"},{"affected":">= 1.0, < 1.4.8","affected_versions_present":true,"cve_id":"CVE-2025-32375","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32375","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-09T15:40:52.656Z","patch_url":"","primary_source":"","published":"2025-04-09T15:30:03.842Z"},{"affected":">= 1.3.4, < 1.4.3","affected_versions_present":true,"cve_id":"CVE-2025-27520","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27520","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-04T14:51:45.561Z","patch_url":"https://github.com/bentoml/BentoML/commit/b35f4f4fcc53a8c3fe8ed9c18a013fe0a728e194","primary_source":"","published":"2025-04-04T14:28:51.574Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"bentoml"}}
