CVE-2025-11157 Overview
CVE-2025-11157 is a high-severity insecure deserialization vulnerability in feast-dev/feast version 0.53.0. The flaw resides in the Kubernetes materializer job at feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py. The code uses yaml.load(..., Loader=yaml.Loader) to parse /var/feast/feature_store.yaml and /var/feast/materialization_config.yaml. This unsafe loader instantiates arbitrary Python objects, allowing an attacker who can modify either YAML file to execute operating system commands on the worker pod. The vulnerability is tracked under [CWE-502] Deserialization of Untrusted Data.
Critical Impact
Successful exploitation enables arbitrary command execution inside the Feast materializer pod, potentially leading to Kubernetes cluster takeover, feature-store data poisoning, and machine-learning supply-chain sabotage.
Affected Products
- feast-dev/feast version 0.53.0
- Red Hat distributions covered by advisory RHSA-2026:10184
- Feast Kubernetes materializer component (sdk/python/feast/infra/compute_engines/kubernetes/main.py)
Discovery Timeline
- 2026-01-01 - CVE-2025-11157 published to NVD
- 2026-07-15 - Last updated in NVD database
Technical Details for CVE-2025-11157
Vulnerability Analysis
The Feast Kubernetes materializer bootstraps a worker pod that reads its runtime configuration from two YAML files mounted at /var/feast/feature_store.yaml and /var/feast/materialization_config.yaml. The original implementation deserialized both files with PyYAML's full yaml.Loader. This loader supports YAML tags such as !!python/object/apply that instruct PyYAML to instantiate arbitrary Python objects and call their constructors during parsing.
Because deserialization occurs before the RepoConfig(**feast_config) validation step, no schema check prevents malicious payloads from executing. An attacker who can write to either configuration file, through a compromised ConfigMap, Secret, mounted volume, or upstream CI pipeline, gains code execution on the worker pod with the service account's Kubernetes permissions.
Root Cause
The root cause is the use of PyYAML's unsafe Loader=yaml.Loader instead of yaml.safe_load. Full loaders resolve Python-specific tags, turning a configuration parser into a general-purpose object instantiation primitive. This pattern maps directly to [CWE-502] Deserialization of Untrusted Data.
Attack Vector
Exploitation requires local write access to the mounted YAML files or upstream control of the artifacts that populate them. A malicious payload using !!python/object/apply:os.system triggers command execution the moment the file is parsed. Because the process runs inside the Feast worker pod, the attacker inherits the pod's service account token and network reach within the cluster.
# Patch from sdk/python/feast/infra/compute_engines/kubernetes/main.py
# Commit b2e37ff37953b68ae833f6874ab5bc510a4ca5fb ("chore: Use Safeload (#5643)")
logging.basicConfig(level=logging.INFO)
with open("/var/feast/feature_store.yaml") as f:
- feast_config = yaml.load(f, Loader=yaml.Loader)
+ feast_config = yaml.safe_load(f)
with open("/var/feast/materialization_config.yaml") as b:
- materialization_cfg = yaml.load(b, Loader=yaml.Loader)
+ materialization_cfg = yaml.safe_load(b)
config = RepoConfig(**feast_config)
store = FeatureStore(config=config)
# Source: https://github.com/feast-dev/feast/commit/b2e37ff37953b68ae833f6874ab5bc510a4ca5fb
Detection Methods for CVE-2025-11157
Indicators of Compromise
- Presence of Python-specific YAML tags such as !!python/object, !!python/object/apply, or !!python/module inside /var/feast/feature_store.yaml or /var/feast/materialization_config.yaml.
- Unexpected child processes (for example /bin/sh, curl, wget) spawned by the Feast materializer Python interpreter inside a Kubernetes worker pod.
- Outbound network connections from Feast materializer pods to unfamiliar hosts shortly after job start.
Detection Strategies
- Scan ConfigMaps, Secrets, and Git-managed manifests for YAML documents containing Python object tags before they are mounted into Feast pods.
- Audit Kubernetes API activity that writes to Feast configuration ConfigMaps or Secrets, especially from non-CI identities.
- Compare the running Feast image and commit hash against b2e37ff37953b68ae833f6874ab5bc510a4ca5fb or the Red Hat advisory RHSA-2026:10184 to identify vulnerable deployments.
Monitoring Recommendations
- Enable runtime process and syscall monitoring on Kubernetes nodes to alert on shell execution originating from the Feast materializer container.
- Forward pod and API-server audit logs into a centralized data lake and correlate configuration writes with subsequent job launches.
- Track image provenance and pin Feast worker images to patched digests through admission control.
How to Mitigate CVE-2025-11157
Immediate Actions Required
- Upgrade Feast beyond version 0.53.0 to a release that contains commit b2e37ff37953b68ae833f6874ab5bc510a4ca5fb ("chore: Use Safeload (#5643)").
- Apply the Red Hat update described in RHSA-2026:10184 on affected distributions.
- Rotate Kubernetes service account tokens and any credentials that were reachable from Feast materializer pods if tampering is suspected.
Patch Information
The upstream fix replaces yaml.load(f, Loader=yaml.Loader) with yaml.safe_load(f) for both feature_store.yaml and materialization_config.yaml. Details are available in the Feast GitHub commit, the Huntr bounty listing, and the Red Hat CVE record.
Workarounds
- Restrict write access to the ConfigMaps, Secrets, and volumes that back /var/feast/feature_store.yaml and /var/feast/materialization_config.yaml using Kubernetes RBAC.
- Mount Feast configuration files as read-only and validate them in CI before deployment to block Python YAML tags.
- Run Feast materializer pods under a minimally privileged service account and apply NetworkPolicies to limit lateral movement if exploitation occurs.
# Verify the mounted configs do not contain unsafe Python YAML tags
kubectl exec -n feast <materializer-pod> -- \
sh -c 'grep -nE "!!python/(object|module|name)" \
/var/feast/feature_store.yaml \
/var/feast/materialization_config.yaml || echo "clean"'
# Pin Feast to a patched version in requirements.txt
# feast>0.53.0 # must include commit b2e37ff37953b68ae833f6874ab5bc510a4ca5fb
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.