CVE-2026-92785

Source
https://cve.org/CVERecord?id=CVE-2026-92785
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92785.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92785
Published
2026-09-16T20:32:41Z
Modified
2026-09-26T03:30:39Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes
Details

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92785.json"
}
References

Affected packages

Git / github.com/angel-ml/angel

Affected ranges

Type
GIT
Repo
https://github.com/angel-ml/angel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "3.3.0"
        },
        {
            "fixed":  "3.3.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

2.*
2.0.0-alpha
Release-2.*
Release-2.0.0
Release-2.0.1
Release-2.0.2
Release-2.2.0
Release-3.*
Release-3.0.0
v1.*
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92785.json"