Incorrect Behavior Order: Early Amplification Affecting feast package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.43% (36th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-FEAST-18612610
  • published11 Aug 2026
  • disclosed10 Aug 2026
  • creditUnknown

Introduced: 10 Aug 2026

NewCVE-2026-18947  (opens in a new tab)
CWE-408  (opens in a new tab)

How to fix?

There is no fixed version for feast.

Overview

feast is a Python SDK for Feast

Affected versions of this package are vulnerable to Incorrect Behavior Order: Early Amplification in the /materialize and /materialize-incremental endpoints. An attacker can trigger a full re-materialization of all feature views, causing denial of service, by sending a specially crafted request that omits the feature_views field. This bypasses the intended permission checks for those endpoints and can be exercised by an unauthenticated remote attacker or any authenticated user. The result is significant resource consumption and data corruption that disrupts service for all tenants.

Notes

  • The issue was originally reported for RedHat's fork of Feast at red-hat-data-services/feast

CVSS Base Scores

version 4.0
version 3.1