Known Vulnerabilities for Feast by Feast-dev
Listed below are 10 of the newest known vulnerabilities associated with "Feast" by "Feast-dev".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92787 json | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all... | Not Provided | 2026-09-16 | 2026-09-19 |
| CVE-2026-56121 json | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to... | Not Provided | 2026-06-24 | 2026-08-28 |
| CVE-2026-55563 json | Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.y... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-23538 json | A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish pe... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-23537 json | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated ... | Not Provided | 2026-07-01 | 2026-07-15 |
| CVE-2026-23536 json | A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote... | Not Provided | 2026-03-20 | 2026-07-15 |
| CVE-2026-18948 json | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are... | Not Provided | 2026-08-10 | 2026-08-27 |
| CVE-2026-18947 json | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endp... | Not Provided | 2026-08-10 | 2026-08-19 |
| CVE-2026-18942 json | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This co... | Not Provided | 2026-08-10 | 2026-08-19 |
| CVE-2026-18941 json | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_... | Not Provided | 2026-08-10 | 2026-08-11 |