Unauthenticated Vulnerability in Angel Product by Tencent
CVE-2026-92785
9.2CRITICAL
What is CVE-2026-92785?
The Angel product up to version 3.3.0 exposes a vulnerability due to the deserialization of untrusted payloads using Kryo without proper class registration and allowlist validation. This flaw allows unauthenticated attackers over the network to create instances of arbitrary classes or potentially exhaust memory on the coordinator by sending specially crafted serialized objects to the master RPC endpoint, leading to potential service disruption and unauthorized access.
Affected Version(s)
angel 0 <= 3.3.0
