Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fpx-xrc2-7qf3

Опубликовано: 05 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 11%
0.00037
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.3
nvd
3 дня назад

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 11%
0.00037
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-20