CVE-2026-92787 Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. This vulnerability enables attackers to gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server, potentially lea [truncated]
CVE-2026-56121 is a critical vulnerability in Feast, a software framework, that allows unauthenticated remote code execution via gRPC deserialization. The vulnerability exists in Feast versions before 0.63.0 and is caused by the unsafe deserialization of user-defined function bodies in OnDemandFeatureView specs. An attacker can exploit this vulnerability by sending a crafted gRPC request to the registry s [truncated]
CVE-2025-11157 is a high-severity remote code execution vulnerability in feast-dev/feast version 0.53.0. The vulnerability exists in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. An attacker can exploit this vulnerability by modifying YAML files to execute OS commands on the worker pod, potentially leading to cluster takeover, data poisoning, [truncated]