What is CVE-2026-18948?
CVE-2026-18948 is a vulnerability in Feast caused by improper deserialization of user-defined functions (UDFs) stored in the registry using the 'dill' library. This flaw allows a remote, unauthenticated attacker to store a malicious UDF, leading to arbitrary code execution on the feature server. Users should immediately update Feast and enforce strict access controls on UDF submissions.
Azərbaycanca: Feast platformasında aşkar edilən CVE-2026-18948 zəifliyi, registry-də saxlanılan və 'dill' kitabxanası ilə seriallaşdırılan user-defined functions (UDFs) komponentlərinin düzgün deserializasiya edilməməsindən qaynaqlanır. Bu boşluq uzaqdan autentifikasiya olunmamış hücumçuya zərərli UDF yükləyərək feature server-də ixtiyari kod icrasına (arbitrary code execution) imkan yaradır. İstifadəçilərə Feast versiyasını təcili yeniləmək və UDF-lər üzərində ciddi giriş nəzarəti tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What is the root cause of CVE-2026-18948?
The vulnerability stems from the improper deserialization of user-defined functions (UDFs) stored in the registry using the 'dill' library in the Feast platform.
How can an attacker exploit this vulnerability?
A remote, unauthenticated attacker can store a malicious UDF, leading to arbitrary code execution on the feature server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.