Feast Feature Server WebSocket Endpoint Resource Exhaustion Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Feast Feature Server, specifically within the '/ws/chat' WebSocket endpoint. This issue allows remote attackers to establish persistent WebSocket connections without authentication. By opening numerous simultaneous connections, an attacker can deplete server resources such as memory, CPU, and file descriptors, causing a complete denial of service for legitimate users. The vulnerability affects Feast Feature Server versions through 0.58.0.

Impact

Exploitation of this vulnerability leads to resource exhaustion, causing high CPU and memory usage, and consuming file descriptors. This resource depletion disrupts service for legitimate users, causing a denial-of-service condition.

Added: Jul 16, 2026, 1:21 AM
Updated: Jul 16, 2026, 1:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.