Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model deserialization | |
| First Time appeared |
Fedml-ai
Fedml-ai fedml |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:fedml-ai:fedml:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedml-ai
Fedml-ai fedml |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T01:45:10.541Z
Reserved: 2026-09-12T19:42:51.777Z
Link: CVE-2026-90614
No data.
Status : Received
Published: 2026-09-14T02:17:15.857
Modified: 2026-09-14T02:17:15.857
Link: CVE-2026-90614
No data.
OpenCVE Enrichment
No data.