PatchSiren

feast-dev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL feast-dev CVE published 2026-09-16

CVE-2026-92787

CVE-2026-92787 Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. This vulnerability enables attackers to gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server, potentially lea [truncated]

CRITICAL feast-dev CVE published 2026-06-24

CVE-2026-56121

CVE-2026-56121 is a critical vulnerability in Feast, a software framework, that allows unauthenticated remote code execution via gRPC deserialization. The vulnerability exists in Feast versions before 0.63.0 and is caused by the unsafe deserialization of user-defined function bodies in OnDemandFeatureView specs. An attacker can exploit this vulnerability by sending a crafted gRPC request to the registry s [truncated]

HIGH feast-dev CVE published 2026-01-01

CVE-2025-11157

CVE-2025-11157 is a high-severity remote code execution vulnerability in feast-dev/feast version 0.53.0. The vulnerability exists in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. An attacker can exploit this vulnerability by modifying YAML files to execute OS commands on the worker pod, potentially leading to cluster takeover, data poisoning, [truncated]