PT-2026-94062 · Angel Ml+1 · Angel

·

CVE-2026-92785

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Angel versions prior to 3.3.1
Description The software deserializes untrusted setAlgoMetrics payloads using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
Recommendations Update Angel to version 3.3.1 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92785

Affected Products

Angel