Bounties
Partners
Community
Info
feast-dev / feast
Project repository
The Open Source Feature Store for Machine Learning
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
30 DAYS
FIX
WITHIN
97 DAYS
Hard-coded non-overridable intra-communication secret in Helm chart enables auth...
Mar 20th 2026
sythenv
•
self closed
Unsafe dill.loads() Deserialization in 9 Locations Enables Remote Code Execution...
Mar 19th 2026
mom3gool2030
•
duplicate
None
Arbitrary Code Execution via Unsafe dill Deserialization of UDF Bodies from Feas...
Mar 19th 2026
kimkou2024
•
duplicate
High
Insecure deserialization of UDF registry blobs leads to RCE
Mar 19th 2026
ghnimiwael
•
duplicate
Critical
Arbitrary File Read / Path Traversal
Mar 29th 2026
luffybounty18
•
pending
Arbitrary code execution during YAML config parsing in Kubernetes materializer
Jan 1st 2026
al-cybision
•
High
High
•
CVE-2025-11157
CVE-2025-11157
Improper CORS Configuration Allowing Unauthorized Cross-Origin Access
Feb 21st 2025
soloplayer140
•
duplicate
High
SQL injection in PostgreSQL offline store
Jan 3rd 2025
ehtec
•
spam
Client-Side Desync Attack: HTTP Request Smuggling Vulnerability in Feast
Dec 18th 2024
samr301
•
not applicable
Client-Side Desync Attack: HTTP Request Smuggling Vulnerability in Feast
Oct 10th 2024
samr301
•
self closed
Remote Code Execution (RCE) in PythonTransformation
Nov 4th 2024
cyfra07
•
informative
Critical
Remote Code Execution (RCE) via Deserialization in Feast GEProfiler
Nov 4th 2024
cyfra07
•
informative
Critical
CORS can leads to expose the sensitive data
Dec 30th 2024
mnqazi
•
High
•
$750
High
•
$750
•
CVE-2024-11602
CVE-2024-11602
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0