
🚨 CVE-2026-56121 | CVSS 9.8 Critical pre-auth RCE affecting Feast in Red Hat OpenShift AI. → Unsafe dill.loads() deserialization before authorization → gRPC ApplyFeatureView / TCP 6570 → No privileges required → Public PoC available → Feast < 0.63.0 affected Action: Upgrade to Feast ≥ 0.63.0 and restrict registry gRPC access to trusted networks. Full Advisory: https://app.transilience.cloud/run-history/da358980-b594-4ddb-91f1-189c78ddd950?file=reports%2Fproducts%2FRed_Hat_OpenShift_AI_Feast_Unsafe_Deserialization_RCE__CVE-2026-18948__red_hat_openshift_ai_feast_unsafe_deserialization_rce__cve-2026-18948__report.pdf #CVE #CyberSecurity #OpenShift
Post summary
A critical pre‑authentication remote code execution flaw (CVE‑2026‑56121) in Feast on Red Hat OpenShift AI allows attackers to execute arbitrary code via unsafe dill.loads deserialization on the gRPC ApplyFeatureView endpoint. A public PoC exists; the advisory recommends upgrading to Feast 0.63.0 or newer and restricting gRPC access to trusted networks.


