CVE-2026-23538 (GCVE-0-2026-23538)
Vulnerability from cvelistv5
Published
2026-07-16 00:10
Modified
2026-07-16 13:58
CWE
  • CWE-770 - Allocation of Resources Without Limits or Throttling
Summary
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file descriptors—leading to a complete denial of service for legitimate users.
Impacted products
Vendor Product Version
Feast Feast Feature Server Version: 0   
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
   Red Hat Red Hat OpenShift AI (RHOAI)     cpe:/a:redhat:openshift_ai
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-feature-server-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_ai"
            ],
            "defaultStatus": "unaffected",
            "packageName": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "vendor": "Red Hat"
          }
        ],
        "datePublic": "2026-03-20T00:00:00.000Z",
        "descriptions": [
          {
            "lang": "en",
            "value": "A vulnerability was identified in the Feast Feature Server\u0027s `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources\u2014such as memory, CPU, and file descriptors\u2014leading to a complete denial of service for legitimate users."
          }
        ],
        "metrics": [
          {
            "other": {
              "content": {
                "namespace": "https://access.redhat.com/security/updates/classification/",
                "value": "Important"
              },
              "type": "Red Hat severity rating"
            }
          },
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 7.5,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
              "version": "3.1"
            },
            "format": "CVSS"
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-770",
                "description": "Allocation of Resources Without Limits or Throttling",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-16T12:04:34.222Z",
          "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "shortName": "redhat-SADP"
        },
        "references": [
          {
            "tags": [
              "vdb-entry",
              "x_refsource_REDHAT"
            ],
            "url": "https://access.redhat.com/security/cve/CVE-2026-23538"
          },
          {
            "name": "RHBZ#2429311",
            "tags": [
              "issue-tracking",
              "x_refsource_REDHAT"
            ],
            "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429311"
          },
          {
            "tags": [
              "x_sadp-csaf-vex"
            ],
            "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23538.json"
          }
        ],
        "timeline": [
          {
            "lang": "en",
            "time": "2026-01-13T19:41:13.224Z",
            "value": "Reported to Red Hat."
          },
          {
            "lang": "en",
            "time": "2026-03-20T00:00:00.000Z",
            "value": "Made public."
          }
        ],
        "title": "feast: Resource exhaustion via WebSocket endpoint",
        "x_adpType": "supplier",
        "x_generator": {
          "engine": "sadp-cli 1.0.0"
        }
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-23538",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-16T13:51:47.243241Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-16T13:58:04.495Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Feast Feature Server",
          "vendor": "Feast",
          "versions": [
            {
              "lessThan": "0.59.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-feature-server-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "defaultStatus": "unaffected",
          "packageName": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "vendor": "Red Hat"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "This issue was discovered by Jitendra Yejare (Red Hat)."
        }
      ],
      "datePublic": "2026-03-20T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was identified in the Feast Feature Server\u0027s `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources\u2014such as memory, CPU, and file descriptors\u2014leading to a complete denial of service for legitimate users."
        }
      ],
      "metrics": [
        {
          "other": {
            "content": {
              "namespace": "https://access.redhat.com/security/updates/classification/",
              "value": "Important"
            },
            "type": "Red Hat severity rating"
          }
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-770",
              "description": "Allocation of Resources Without Limits or Throttling",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-16T00:10:50.170Z",
        "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "shortName": "redhat"
      },
      "references": [
        {
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ],
          "url": "https://access.redhat.com/security/cve/CVE-2026-23538"
        },
        {
          "name": "RHBZ#2429311",
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ],
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2429311"
        },
        {
          "url": "https://github.com/red-hat-data-services/feast/pull/192"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-01-13T19:41:13.224Z",
          "value": "Reported to Red Hat."
        },
        {
          "lang": "en",
          "time": "2026-03-20T00:00:00.000Z",
          "value": "Made public."
        }
      ],
      "title": "Feast: resource exhaustion via websocket endpoint",
      "workarounds": [
        {
          "lang": "en",
          "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
        }
      ],
      "x_generator": {
        "engine": "cvelib 1.8.0"
      },
      "x_redhatCweChain": "CWE-770: Allocation of Resources Without Limits or Throttling"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
    "assignerShortName": "redhat",
    "cveId": "CVE-2026-23538",
    "datePublished": "2026-07-16T00:10:50.170Z",
    "dateReserved": "2026-01-13T19:53:18.502Z",
    "dateUpdated": "2026-07-16T13:58:04.495Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"cna\": {\"title\": \"Feast: resource exhaustion via websocket endpoint\", \"metrics\": [{\"other\": {\"content\": {\"value\": \"Important\", \"namespace\": \"https://access.redhat.com/security/updates/classification/\"}, \"type\": \"Red Hat severity rating\"}}, {\"cvssV3_1\": {\"attackComplexity\": \"LOW\", \"attackVector\": \"NETWORK\", \"availabilityImpact\": \"HIGH\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"confidentialityImpact\": \"NONE\", \"integrityImpact\": \"NONE\", \"privilegesRequired\": \"NONE\", \"scope\": \"UNCHANGED\", \"userInteraction\": \"NONE\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\", \"version\": \"3.1\"}, \"format\": \"CVSS\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability was identified in the Feast Feature Server\u0027s `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources\\u2014such as memory, CPU, and file descriptors\\u2014leading to a complete denial of service for legitimate users.\"}], \"affected\": [{\"vendor\": \"Feast\", \"product\": \"Feast Feature Server\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"0.59.0\", \"versionType\": \"semver\"}], \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-feature-server-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}, {\"vendor\": \"Red Hat\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"packageName\": \"rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9\", \"defaultStatus\": \"unaffected\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"]}], \"references\": [{\"url\": \"https://access.redhat.com/security/cve/CVE-2026-23538\", \"tags\": [\"vdb-entry\", \"x_refsource_REDHAT\"]}, {\"url\": \"https://bugzilla.redhat.com/show_bug.cgi?id=2429311\", \"name\": \"RHBZ#2429311\", \"tags\": [\"issue-tracking\", \"x_refsource_REDHAT\"]}, {\"url\": \"https://github.com/red-hat-data-services/feast/pull/192\"}], \"datePublic\": \"2026-03-20T00:00:00.000Z\", \"problemTypes\": [{\"descriptions\": [{\"cweId\": \"CWE-770\", \"description\": \"Allocation of Resources Without Limits or Throttling\", \"lang\": \"en\", \"type\": \"CWE\"}]}], \"x_redhatCweChain\": \"CWE-770: Allocation of Resources Without Limits or Throttling\", \"workarounds\": [{\"lang\": \"en\", \"value\": \"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\"}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2026-01-13T19:41:13.224Z\", \"value\": \"Reported to Red Hat.\"}, {\"lang\": \"en\", \"time\": \"2026-03-20T00:00:00.000Z\", \"value\": \"Made public.\"}], \"credits\": [{\"lang\": \"en\", \"value\": \"This issue was discovered by Jitendra Yejare (Red Hat).\"}], \"providerMetadata\": {\"orgId\": \"53f830b8-0a3f-465b-8143-3b8a9948e749\", \"shortName\": \"redhat\", \"dateUpdated\": \"2026-07-16T00:10:50.170Z\"}, \"x_generator\": {\"engine\": \"cvelib 1.8.0\"}}, \"adp\": [{\"affected\": [{\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-feature-server-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}, {\"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"cpes\": [\"cpe:/a:redhat:openshift_ai\"], \"defaultStatus\": \"unaffected\", \"packageName\": \"rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9\", \"product\": \"Red Hat OpenShift AI (RHOAI)\", \"vendor\": \"Red Hat\"}], \"datePublic\": \"2026-03-20T00:00:00.000Z\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability was identified in the Feast Feature Server\u0027s `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources\\u2014such as memory, CPU, and file descriptors\\u2014leading to a complete denial of service for legitimate users.\"}], \"metrics\": [{\"other\": {\"content\": {\"namespace\": \"https://access.redhat.com/security/updates/classification/\", \"value\": \"Important\"}, \"type\": \"Red Hat severity rating\"}}, {\"cvssV3_1\": {\"attackComplexity\": \"LOW\", \"attackVector\": \"NETWORK\", \"availabilityImpact\": \"HIGH\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"confidentialityImpact\": \"NONE\", \"integrityImpact\": \"NONE\", \"privilegesRequired\": \"NONE\", \"scope\": \"UNCHANGED\", \"userInteraction\": \"NONE\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\", \"version\": \"3.1\"}, \"format\": \"CVSS\"}], \"problemTypes\": [{\"descriptions\": [{\"cweId\": \"CWE-770\", \"description\": \"Allocation of Resources Without Limits or Throttling\", \"lang\": \"en\", \"type\": \"CWE\"}]}], \"references\": [{\"tags\": [\"vdb-entry\", \"x_refsource_REDHAT\"], \"url\": \"https://access.redhat.com/security/cve/CVE-2026-23538\"}, {\"name\": \"RHBZ#2429311\", \"tags\": [\"issue-tracking\", \"x_refsource_REDHAT\"], \"url\": \"https://bugzilla.redhat.com/show_bug.cgi?id=2429311\"}, {\"tags\": [\"x_sadp-csaf-vex\"], \"url\": \"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23538.json\"}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2026-01-13T19:41:13.224Z\", \"value\": \"Reported to Red Hat.\"}, {\"lang\": \"en\", \"time\": \"2026-03-20T00:00:00.000Z\", \"value\": \"Made public.\"}], \"title\": \"feast: Resource exhaustion via WebSocket endpoint\", \"x_adpType\": \"supplier\", \"x_generator\": {\"engine\": \"sadp-cli 1.0.0\"}, \"providerMetadata\": {\"orgId\": \"0b0ca135-0b70-47e7-9f44-1890c2a1c46c\", \"shortName\": \"redhat-SADP\", \"dateUpdated\": \"2026-07-16T12:04:34.222Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-23538\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-16T13:51:47.243241Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-16T13:58:00.516Z\"}}]}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-23538\", \"assignerOrgId\": \"53f830b8-0a3f-465b-8143-3b8a9948e749\", \"state\": \"PUBLISHED\", \"assignerShortName\": \"redhat\", \"dateReserved\": \"2026-01-13T19:53:18.502Z\", \"datePublished\": \"2026-07-16T00:10:50.170Z\", \"dateUpdated\": \"2026-07-16T13:58:04.495Z\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…