CVE-2026-35044: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35044 is a Server-Side Template Injection (SSTI) vulnerability in BentoML, a Python library for building AI model serving systems. The flaw exists in the generate_containerfile() function, which uses an unsandboxed jinja2.Environment with dangerous extensions to render user-provided Dockerfile templates embedded in bento archives. All BentoML versions prior to 1.4.38 are affected. The vulnerability was published on April 6, 2026, and patched in version 1.4.38 released shortly after. It carries a CVSS v3.1 base score of 9.6 (Critical) per Feedly threat intelligence data, though the GitHub advisory scores it 8.8 (High) (GitHub Advisory).

Technical details

The root cause is CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). The vulnerable code in src/bentoml/_internal/container/generate.py (lines 155–157) instantiates a standard jinja2.Environment — not a sandboxed variant — with the jinja2.ext.do extension enabled, which allows {% do %} tags to execute arbitrary Python expressions, and jinja2.ext.debug, which exposes internal template engine state. An attacker crafts a malicious bento archive containing a Dockerfile.template with injected Jinja2 payload code; when a victim runs bentoml containerize, the template is loaded and rendered on the host machine before any Docker container is created, bypassing all container isolation. Exploitation requires user interaction (the victim must import and containerize the malicious archive) but no authentication or special privileges (GitHub Advisory).

Impact

Successful exploitation grants an attacker arbitrary Python code execution directly on the victim's host machine, with the same privileges as the user running bentoml containerize. This exposes the full host filesystem — including source code, SSH keys, cloud tokens, API keys, and database credentials stored in environment variables — and enables installation of backdoors or lateral movement to other systems. The attack is especially dangerous in CI/CD environments, where the compromised machine may have broad network access and elevated permissions, creating supply chain compromise risk (GitHub Advisory).

Exploitability

A proof-of-concept exploit with a complete step-by-step attack sequence, including exact Jinja2 payloads and bash commands, is publicly available in the GitHub Security Advisory (GitHub Advisory). Feedly classifies the PoC confidence as high, noting it provides a concrete reproducible attack flow. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.041% (0.000410), indicating low but non-zero probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Craft malicious template: Create a Jinja2 template file evil.j2 containing an SSTI payload, e.g.:
{% extends bento_base_template %}
{% block SETUP_BENTO_COMPONENTS %}
{{ super() }}
{% do namespace.__init__.__globals__['__builtins__']['__import__']('os').system('id > /tmp/pwned') %}
{% endblock %}
  1. Configure bentofile: Create a bentofile.yaml referencing the malicious template:
service: 'service:MyService'
docker:
  dockerfile_template: ./evil.j2
  1. Build and export the bento: Run bentoml build followed by bentoml export myservice:latest bento.tar to package the malicious template inside the archive.
  2. Distribute the archive: Share the bento.tar file via S3, HTTP, direct transfer, or any other channel to the intended victim.
  3. Victim imports the archive: Victim runs bentoml import bento.tar — no validation of template content is performed at this stage.
  4. Trigger code execution: Victim runs bentoml containerize myservice:latest; the unsandboxed Jinja2 environment renders the attacker-controlled template on the host, executing the injected Python payload before any Docker container is created.
  5. Verify compromise: The attacker's command (e.g., id > /tmp/pwned) executes as the victim's user account on the host machine (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files created in /tmp/ or other writable directories (e.g., /tmp/pwned) during a bentoml containerize operation; presence of Dockerfile.template inside a bento archive at env/docker/Dockerfile.template containing {% do %} or {% debug %} Jinja2 tags; new or modified cron jobs, SSH authorized_keys, or startup scripts created by the user running BentoML.
  • Process: Unexpected child processes spawned by the Python process running bentoml containerize, such as bash, sh, curl, wget, or python3 executing commands not related to Docker build operations.
  • Logs: Python tracebacks or unusual output from bentoml containerize commands; shell command output (e.g., uid=...) appearing in the terminal during containerization where only Docker build logs are expected.
  • Network: Outbound connections to unknown external hosts initiated by the Python process during bentoml containerize execution, potentially indicating reverse shell or data exfiltration activity (GitHub Advisory).

Mitigation and workarounds

Upgrade BentoML to version 1.4.38 or later, which replaces the unsandboxed jinja2.Environment with jinja2.sandbox.SandboxedEnvironment and removes the dangerous jinja2.ext.do and jinja2.ext.debug extensions. As an immediate workaround, avoid importing or running bentoml containerize on bento archives from untrusted or unverified sources. Organizations should manually inspect any bento archive's env/docker/Dockerfile.template for suspicious {% do %} or {% debug %} Jinja2 tags before containerizing. CI/CD pipelines that process externally sourced bento archives should be treated as high-risk until upgraded (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher frostming and published via GitHub Security Advisories on April 2, 2026. Coverage appeared across security aggregators including The Hacker Wire, VulDB, CVEFeed, and Tenable's plugin pipeline shortly after disclosure. Social media discussion was noted on Bluesky and Mastodon via The Hacker Wire's account. The yazoul.net advisory specifically highlighted the RCE-in-containerize attack path. Overall community sentiment reflects concern about supply chain risk, given that the attack vector involves distributing seemingly legitimate bento model archives (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-jqmf-mx4f-hfr6CRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-8mcx-5rqc-vhmfHIGH8.8
  • Python logoPython
  • dulwich
NoYesOct 02, 2026
GHSA-5rmq-chc7-m22fHIGH7.5
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-35mr-4567-66vgMEDIUM6.5
  • Python logoPython
  • dulwich
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management