VYPR
Unrated severityNVD Advisory· Published Mar 20, 2026· Updated Mar 24, 2026

Feast: unauthenticated arbitrary file read

CVE-2026-23536

Description

A security issue was discovered in the Feast Feature Server's /read-document endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.

Affected products

2
  • Red Hat/Red Hat OpenShift AI (RHOAI)v5
    cpe:/a:redhat:openshift_ai
  • Feast Dev/Feastllm-fuzzy

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.