VDB
CVE-2025-11157
CVE-2025-11157
PUBLISHED
CVSS 7.800000190734863 HIGH
Feast vulnerable to Deserialization of Untrusted Data
EPSS 0.30% · 20.0th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.30%
20.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI 2.25 | 1776338381 |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| feast-dev | feast-dev/feast | unspecified, * |
| PyPI | feast | 0, 0 |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) |
Timeline
- Jan 1, 2026 CVE Published
- Jan 1, 2026 EPSS Score
- Jan 1, 2026 PoC Published
- Jan 1, 2026 PoC Published
- Jan 2, 2026 CVE Updated
- Jan 2, 2026 PoC Published
- Jan 2, 2026 PoC Published
- Jan 5, 2026 EPSS Score
- Jan 9, 2026 EPSS Score
- Jan 12, 2026 EPSS Score
- Jan 16, 2026 EPSS Score
- Jan 20, 2026 EPSS Score
References
- https://access.redhat.com/errata/RHSA-2026:10184 advisory
- https://access.redhat.com/security/cve/CVE-2025-11157 advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-11157.json advisory
- https://github.com/feast-dev/feast/pull/5643 fix
- https://github.com/feast-dev/feast/commit/b2e37ff37953b68ae833f6874ab5bc510a4ca5fb fix
- https://bugzilla.redhat.com/show_bug.cgi?id=2426574 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-11157 advisory
- https://github.com/feast-dev/feast package
- https://huntr.com/bounties/46d4d585-b968-4a76-80ce-872bc5525564 url