HIGH
CVE-2026-92785
CVSS
8.1
Description
Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
0.36%
Probability of exploitation in next 30 days
29.6th percentile
References
https://github.com/Angel-ML/angel
https://github.com/Angel-ML/angel/blob/Release-3.3.0/angel-ps/core/src/main/java/com/tencent/angel/utils/KryoUtils.java#L45-L70
https://github.com/Angel-ML/angel/issues/1355
https://www.vulncheck.com/advisories/angel-through-3.3.0-unauthenticated-kryo-deserialization-of-arbitrary-classes
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.