Loading market data...
← Back to CVE feed

CVE-2026-92785

HIGH CVSS 8.1 View on NVD ↗

Description

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Sep 16, 2026 21:17 UTC Modified: Sep 17, 2026 16:18 UTC