Vulnerability  ·  2026-09-15

FedML — insecure deserialization in S3/MQTT model-storage backend

VulnerabilityMedium impactGlobalCVE-2026-90614
FedML is a federated-learning framework; insecure deserialization in the model-loading path can lead to remote code execution on a federated-learning coordinator or worker node if an attacker can influence the S3 key used to fetch model artifacts.
S3Storage.read_model in the MQTT+S3 communication backend deserializes data referenced by an attacker-influenced s3_key_str argument, enabling remote deserialization of untrusted data.
FedML-AI FedML up to 0.9.6
No response from maintainers at time of publication (issue reported early); avoid untrusted s3_key_str inputs and restrict access to the federated-learning communication backend until patched.
FedML GitHub issue #2267NVD CVE-2026-90614
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →