CVE-2026-35171Disclosure(linuxfoundation / kedro)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation kedro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration schema supports the special () key, which enables arbitrary callable instantiation. An attacker can exploit this to execute arbitrary system commands during application startup. This is a critical remote code execution (RCE) vulnerability caused by unsafe use of logging.config.dictConfig() with user-controlled input. This vulnerability is fixed in 1.3.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kedro

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-06)
  • 5 total mentions across 2 days

Affected systems

Products
kedro

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-03: 2Mentions · 2026-04-06: 3Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-06: 304-0304-06
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-063
Disclosure2Patch1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35171: CRITICAL] Critical RCE vulnerability in Kedro before 1.3.0 allows attackers to execute system commands via a specially crafted logging configuration file. Upgrade to version 1.3.0 for a fix.#cve,CVE-2026-35171,#cybersecurity https://cvefind.com/CVE-2026-35171

    Post summary

    The post alerts about a critical RCE in Kedro prior to 1.3.0 and advises upgrading to version 1.3.0 to remediate the issue.

    0000051
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35171 Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environm… https://www.cve.org/CVERecord?id=CVE-2026-35171

    Post summary

    The post discloses a configuration vulnerability in Kedro that permits the logging configuration file path to be set via an environment variable, referring readers to the CVE record for details.

    0000086
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35171: Arbitrary Code Execution via Mal... Environment variable poisoning meets Python's logging.config.dictConfig() - RCE via the `()` callable key is textbook d... https://zerodaysignal.com/vulnerability/CVE-2026-35171 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new CVE-2026-35171 vulnerability is disclosed, leveraging environment variable poisoning in Python's logging.config.dictConfig() to achieve arbitrary code execution via a callable key; no PoC, exploit, active use, or patch is mentioned.

    0000068
    204 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Kedro` is vulnerable to arbitrary code execution via malicious logging configuration (CVE-2026-35171). Assess configuration sources and project dependencies. #Python #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-35171-kedro-rce-malicious-logging-config

    Post summary

    The post announces an arbitrary‑code‑execution CVE (CVE‑2026‑35171) in Kedro caused by malicious logging configuration, urging users to review configurations, but it offers no PoC, exploit code, or patch details.

    0000046
    10 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical Kedro flaw: CVE-2026-35171 This issue could allow arbitrary code execution in affected environments. Upgrade now or apply the recommended workaround. 🔗 https://vulert.com/vuln-db/CVE-2026-35171 #CyberSecurity #Kedro #CVE202635171 #Vulert https://t.co/5QJ8mP13GX

    Post summary

    The tweet announces a critical Kedro vulnerability (CVE‑2026‑35171) that could allow arbitrary code execution, and urges affected users to upgrade or apply the recommended workaround.

    0000033
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationkedro-python-

Explore more