CVE-2026-5536: FedML-AI FedML gRPC server grpc_server.py sendMessage deserialization
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpcserver.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5536?
CVE-2026-5536 is classified as a moderate severity vulnerability due to the potential for deserialization attacks.
How do I fix CVE-2026-5536?
To mitigate CVE-2026-5536, update the FedML package to a version later than 0.8.9.
What component is affected by CVE-2026-5536?
CVE-2026-5536 affects the sendMessage function in the grpc_server.py component of the FedML gRPC server.
What kind of attack is possible with CVE-2026-5536?
CVE-2026-5536 allows for deserialization attacks through the exploitation of the affected gRPC server.
Which versions of FedML are vulnerable to CVE-2026-5536?
FedML versions up to 0.8.9 are vulnerable to CVE-2026-5536.