Deserialization Flaw in Feast Affects Red Hat's Feature Server and Registry
CVE-2026-18948
9.9CRITICAL
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-18948?
A deserialization flaw found in Feast allows remote attackers to exploit improperly deserialized user-defined functions (UDFs) stored in its registry. This vulnerability can enable unauthenticated arbitrary code execution on the feature server when configured with default settings. Additionally, authenticated attackers may bypass authorization checks, facilitating code execution on the registry server. The implications of this flaw pose risks such as cross-tenant data access and lateral movement within the system, endangering the overall security posture.
Affected Version(s)
Red Hat OpenShift AI 2.25 1786110051
Red Hat OpenShift AI 3.3 1786110033
Red Hat OpenShift AI 3.4 1786107278