VYPR

Feast

by Red Hat

CVEs (2)

  • CVE-2026-23538HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server…

  • CVE-2026-23537CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.01

    A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can…