Skip to content
Red HatCVE-2026-23537

Red Hat Feast Feature Server: denial of service

Critical9.1CVE-2026-23537 · Published Jul 1, 2026 · updated Jul 15, 2026

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the server can potentially compromise the integrity of the system. This could lead to unauthorized system modifications, denial of service through disk exhaustion, or potential remote code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Feast Feature Server
Product
< 0.59.00.59.0
Red Hat OpenShift AI (RHOAI)
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: improper access control
Medium6.5Jul 1
Red Hat Satellite 6: information disclosure
Medium4.3Jul 1
Red Hat Satellite 6: information disclosure
Medium6.5Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Satellite 6: privilege escalation
High8.8Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.