{"id":"CVE-2026-35052","aliases":["GHSA-436g-fhfc-9g5w","PYSEC-2026-2460"],"title":"D-Tale: Remote Code Execution through redis/shelf storage","summary":"D-Tale: Remote Code Execution through redis/shelf storage","severity":"medium","vendor":"dtale","product":"dtale","ecosystem":"pip","affected":["dtale < 3.22.0"],"patched":["dtale 3.22.0"],"published":"2026-04-03","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-436g-fhfc-9g5w","references":[{"url":"https://github.com/man-group/dtale/security/advisories/GHSA-436g-fhfc-9g5w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35052"},{"url":"https://github.com/man-group/dtale"}],"tags":["osv","pip"],"epss":0.00622,"epssPercentile":0.48486,"ingestedAt":"2026-07-13T18:57:52.249Z","slug":"CVE-2026-35052","body":"## Overview\n\n### Impact\nUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server.\n\n### Patches\nUsers should upgrade to version 3.22.0.\n\n### Workarounds\nThere are no workarounds for versions < 3.22.0\n\n## Affected packages\n\n- `dtale < 3.22.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `dtale 3.22.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}