No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model deserialization | |
| First Time appeared |
Fedml-ai
Fedml-ai fedml |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:fedml-ai:fedml:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedml-ai
Fedml-ai fedml |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T01:45:10.541Z
Reserved: 2026-09-12T19:42:51.777Z
Link: CVE-2026-90614
No data.
Status : Received
Published: 2026-09-14T02:17:15.857
Modified: 2026-09-14T02:17:15.857
Link: CVE-2026-90614
No data.
OpenCVE Enrichment
No data.