CRITICAL 9.2 NVD

CVE-2026-92785

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attacke

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.

References

Published: 2026-09-16 · Source: NVD · Feed updated: 2026-09-16
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-16 via NVD.

Risk Timeline

CVE Disclosed2026-09-16 · -1 days ago

Remediation Resources

vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.