---
id: CVE-2026-90614
title: A weakness has been identified in FedML-AI FedML up to 0.9.6
summary: >-
  A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this
  issue is the function S3Storage.read_model of the file
  fedml/core/distributed/communication/s3/remote_storage.py of the component
  MQTT+S3 Communication Backen…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-20
  - CWE-502
vendor: FedML-AI
product: FedML
affected:
  - FedML 0.9.0
  - FedML 0.9.1
  - FedML 0.9.2
  - FedML 0.9.3
  - FedML 0.9.4
  - FedML 0.9.5
  - FedML 0.9.6
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90614'
references:
  - url: 'https://github.com/FedML-AI/FedML/'
    label: cna@vuldb.com
  - url: 'https://github.com/FedML-AI/FedML/issues/2267'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90614'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/914219'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403196'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403196/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T15:01:46.162945Z'
ingestedAt: '2026-09-14T15:23:07.426Z'
epss: 0.00431
epssPercentile: 0.34559
---

## Overview

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
