HIGH

CVE-2026-92785

2026-09-16 CVSS v3.1
CVSS
8.1

Description

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

0.36%
Probability of exploitation in next 30 days
29.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE