CVEFind.com@CveFindComPatch
The post alerts about a critical RCE in Kedro prior to 1.3.0 and advises upgrading to version 1.3.0 to remediate the issue.
CVE@CVEnewDisclosure
The post discloses a configuration vulnerability in Kedro that permits the logging configuration file path to be set via an environment variable, referring readers to the CVE record for details.
0day Signal@0dayPublishingDisclosure
A new CVE-2026-35171 vulnerability is disclosed, leveraging environment variable poisoning in Python's logging.config.dictConfig() to achieve arbitrary code execution via a callable key; no PoC, exploit, active use, or patch is mentioned.
PulsePatch.io@pulsepatchioDisclosure
The post announces an arbitrary‑code‑execution CVE (CVE‑2026‑35171) in Kedro caused by malicious logging configuration, urging users to review configurations, but it offers no PoC, exploit code, or patch details.
Vulert@vulert_officialPatch
The tweet announces a critical Kedro vulnerability (CVE‑2026‑35171) that could allow arbitrary code execution, and urges affected users to upgrade or apply the recommended workaround.