CVE-2026-23538
Feast Feast Feature Server, Red Hat OpenShift AI (RHOAI)
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file descriptors—leading to a complete denial of service for legitimate users.
- CVSS
- 7.5
- EPSS
- 0.75% 51.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.16