CVE-2026-56121 is an unsafe deserialization vulnerability in Feast versions prior to 0.63.0 affecting the registry server's gRPC interface. When processing an OnDemandFeatureView specification, the server decodes the user_defined_function.body field from base64 and passes the result to dill.loads() before completing any authorization check. Because dill deserialization can invoke attacker-controlled Python object behavior such as a crafted reduce method, a malicious gRPC request can trigger arbitrary code execution during request handling. The flaw is remotely exploitable and can be reached by unauthenticated or otherwise unauthorized attackers if they can send requests to the registry server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Python exploit repository for an alleged Feast registry-server unsafe-deserialization vulnerability, CVE-2026-56121. The principal client, exploit/exploit.py, creates an ApplyFeatureView gRPC request containing an OnDemandFeatureView in pandas mode. Its UserDefinedFunctionV2.body contains a standard-library pickle gadget that causes exec(attacker_source) when the vulnerable server calls dill.loads during request parsing. The exploit relies on this parsing occurring before the authorization check, allowing unauthenticated RCE where Feast is configured with no_auth. The payload can execute arbitrary /bin/sh commands and send combined output to a temporary TCP listener, create a /tmp proof marker and return basic host details, or establish an interactive /bin/sh reverse shell. exploit/poc.py is a shorter equivalent command-execution PoC. The committed exploit/protos/ tree contains generated Feast v0.62.0 protobuf and gRPC client stubs, while build_protos.sh optionally downloads source .proto definitions and regenerates those stubs in a pinned toolchain. The lab/ directory supplies a Dockerized Feast 0.62.0 environment, exposing TCP/6570, initializing a minimal rce_demo feature repository, and deliberately setting auth.type to no_auth. Documentation states the affected range is Feast <0.63.0 and that version 0.63.0 corrects the authorization/deserialization ordering.
This repository is a small, self-contained Python proof-of-concept exploit for CVE-2026-56121 affecting the Feast registry gRPC server. The repo contains only two files: a README describing the vulnerability, prerequisites, and usage, and a single executable script, exploit.py, which is the exploit entry point. The exploit targets Feast versions earlier than 0.63.0. It abuses the ApplyFeatureView gRPC method, which reconstructs an OnDemandFeatureView from attacker-controlled protobuf data and deserializes spec.user_defined_function.body with dill.loads() before authorization. The script creates a malicious Python object whose __reduce__ method returns os.system with an attacker-supplied command, serializes it with pickle, embeds it into a UserDefinedFunction body, wraps that in an OnDemandFeatureViewSpec and ApplyFeatureViewRequest, and sends it to the target using an insecure gRPC channel. Primary capability: unauthenticated remote command execution over the network against a reachable Feast registry service, typically on port 6570. The exploit does not retrieve command output directly; instead, output is expected on the server’s stdout/journal, so the README suggests using a reverse shell or writing results to a readable location. The code anticipates that the RPC may fail after deserialization and treats a grpc.RpcError as expected behavior after payload execution. Repository structure is minimal and purpose-built: README.md documents the vulnerability and exploitation workflow; exploit.py implements argument parsing, payload construction, protobuf object creation, and RPC delivery. No persistence, evasion, scanning, or multi-target automation is present.
This repository is a compact proof-of-concept exploit for CVE-2026-56121 affecting Feast registry gRPC servers prior to 0.63.0. The main exploit is exploit.py, a standalone Python script that connects to a target Feast registry over gRPC using an insecure channel and sends a crafted ApplyFeatureView request. The request embeds a malicious Python pickle in OnDemandFeatureView.spec.feature_transformation.user_defined_function.body. On vulnerable servers, Feast deserializes this field with dill.loads() during from_proto processing before authorization checks, causing immediate execution of the attacker-supplied os.system command. Repository structure is simple: exploit.py contains the active exploit logic; README.md documents the vulnerability, exploitation steps, impact, and remediation; ANALYSIS.md provides code-path and patch-level analysis of the vulnerable Feast internals; lab/Dockerfile and lab/docker-compose.yml build a reproducible vulnerable environment using feast==0.62.0 and expose the registry service on port 6570. Exploit capabilities: arbitrary command execution on the remote registry host, with user-supplied command selection via -c/--cmd. The default command writes output to /tmp/feast_pwned for verification. The exploit does not establish persistence, a shell listener, or post-exploitation automation; it is a direct RCE trigger PoC. The RPC may return an error after deserialization because the unpickled object is not a valid UDF, but that does not prevent command execution. The attack vector is network-based against the Feast registry gRPC service. The exploit specifically targets the ApplyFeatureView RPC and relies on the vulnerable server deserializing attacker-controlled bytes from the user_defined_function.body field. The included lab environment demonstrates the intended target configuration: Feast 0.62.0, default no_auth behavior, and registry service reachable on port 6570.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Feast's gRPC registry server caused by unsafe deserialization, affecting versions prior to 0.63.0 when the registry server is explicitly started.
An unauthenticated remote code execution vulnerability in Feast before 0.63.0 caused by unsafe deserialization of user-controlled data in ApplyFeatureView gRPC processing.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.