Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint. | |
| Title | Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:03:38.116Z
Reserved: 2026-09-16T19:22:55.254Z
Link: CVE-2026-92785
Updated: 2026-09-17T15:03:34.856Z
Status : Received
Published: 2026-09-16T21:17:27.730
Modified: 2026-09-17T16:18:33.557
Link: CVE-2026-92785
No data.
OpenCVE Enrichment
No data.