Junglewise Threat Intelligence

CVE-2026-23538: Feast Feature Server resource exhaustion in WebSocket chat endpoint

CVE-2026-23538 · Severity: high · CVSS 7.5 · Published 2026-07-16

Vendors: Red Hat.

Executive brief

A vulnerability in the Feast Feature Server, a tool used to manage and serve data for machine learning models, allows unauthorized users to crash the service. By opening many simultaneous connections to a specific chat feature, an attacker can overwhelm the server's memory and processing power. This results in a total denial of service, preventing legitimate users and applications from accessing critical machine learning data.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in the Feast Feature Server's `/ws/chat` WebSocket endpoint. The endpoint allows unauthenticated remote attackers to establish and maintain persistent WebSocket connections without restriction. By initiating a large volume of simultaneous connections, an attacker can exhaust critical system resources including memory, CPU cycles, and file descriptors. This leads to a complete denial of service (DoS) for the feature server. The issue is addressed in version 0.59.0 and via specific patches in Red Hat OpenShift AI components.

Affected products

  • Feast Feast Feature Server < 0.59.0
  • Red Hat Red Hat OpenShift AI (RHOAI) Affected

Timeline

  • 2026-01-13: disclosed: Reported to Red Hat Bugzilla
  • 2026-01-16: patched: Fix merged in GitHub pull request 192
  • 2026-07-16: advisory: NVD publication date

References