Vendor
Unauthenticated RCE and Data Access in Feast via Default Configuration
3 TTPs 1 CVEFeast and feast-operator contain a vulnerability due to a default 'no_auth' configuration, allowing unauthenticated attackers to achieve RCE via malicious User-Defined Functions and perform unauthorized cross-tenant data access.
Critical Arbitrary Code Execution in Feast via UDF Deserialization
1 rule 4 TTPs 1 CVEFeast improperly deserializes user-defined functions via the 'dill' library, allowing remote unauthenticated attackers to achieve arbitrary code execution on feature servers.
Feast Feature Server Denial of Service via Unauthenticated WebSocket Connections (CVE-2026-23538)
1 rule 1 TTP 1 CVEA vulnerability (CVE-2026-23538) exists in the Feast Feature Server's /ws/chat endpoint, allowing remote attackers to establish numerous unauthenticated, persistent WebSocket connections. This exploit, a form of resource exhaustion (CWE-770), consumes server resources like memory, CPU, and file descriptors, leading to a complete denial of service for legitimate users. Affected versions are those prior to 0.59.0.