CVE-2026-18948
Received Received - Intake

Feast Deserialization Flaw Leads to Code Execution

Vulnerability report for CVE-2026-18948, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
feast feast *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Feast involves improper deserialization of user-defined functions (UDFs) stored in its registry. These UDFs are serialized using the 'dill' library, which allows a remote attacker to store a malicious UDF. This leads to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also bypass authorization checks during deserialization to achieve arbitrary code execution on the registry server.

Impact Analysis

This vulnerability can allow attackers to execute arbitrary code on affected systems. For users of Feast, this could result in unauthorized access to sensitive data, potential data breaches, and lateral movement within the system. Cross-tenant data access is also possible, meaning attackers could access data from other tenants in a multi-tenant environment.

Compliance Impact

This vulnerability could lead to data breaches, which may violate compliance requirements under GDPR, HIPAA, and other regulations. Unauthorized access to sensitive data could result in legal penalties, reputational damage, and loss of trust. Organizations using Feast must address this issue to maintain compliance with data protection standards.

Mitigation Strategies

Disable or restrict access to the Feast feature server and registry server until patches are applied. Ensure network segmentation prevents unauthorized access to these components. Review and remove any untrusted user-defined functions (UDFs) from the registry. Monitor for suspicious activity related to deserialization or code execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18948. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart