Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56121

Опубликовано: 24 июн. 2026
Источник: nvd
CVSS3: 9.8
CVSS3: 8.8
EPSS Низкий

Описание

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary reduce method to execute OS commands as the feast service account.

EPSS

Процентиль: 64%
0.01143
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 8.8
redhat
около 1 месяца назад

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary __reduce__ method to execute OS commands as the feast service account.

CVSS3: 9.8
github
около 1 месяца назад

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary __reduce__ method to execute OS commands as the feast service account.

EPSS

Процентиль: 64%
0.01143
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-502
CWE-502