CVE-2026-35052Medium▾ SunlitD-Tale: Remote Code Execution through redis/shelf storage
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
Users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server.
Users should upgrade to version 3.22.0.
There are no workarounds for versions < 3.22.0
dtale < 3.22.0Upgrade to a patched release:
dtale 3.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
CVE-2024-55890MediumD-Tale allows Remote Code Execution through the Custom Filter Input
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads