CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56121

Critical · CVSS 9.8

Feast (feast-dev/feast) — Unsafe deserialization RCE via dill.loads() in gRPC registry server

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-502, CWE-502

Description

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary __reduce__ method to execute OS commands as the feast service account.

Search profile — drives PoC discovery

Symbols user_defined_function.bodydill.loadsOnDemandFeatureViewApplyFeatureView__reduce__RegistryServerbase64
Keywords CVE-2026-56121Feast deserialization RCEfeast dill.loads exploitOnDemandFeatureView unsafe deserializationfeast gRPC registry server RCEfeast unauthenticated RCEfeast ApplyFeatureView PoCfeast-dev feast CVE-2026-56121feast 0.63.0 vulnerability
Versions: < 0.63.0

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z