CVE-2026-90614 | FedML-AI FedML up to 0.9.6 MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model s3_key_str deserialization (Issue 2267)

SecurityVulns

A vulnerability identified as critical has been detected in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization.

This vulnerability is registered as CVE-2026-90614. Remote exploitation of the attack is possible. No exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More