
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35052 is a Remote Code Execution (RCE) vulnerability in D-Tale, an open-source Flask/React web client for visualizing pandas DataFrames maintained by Man Group. The flaw affects all D-Tale versions prior to 3.22.0 and is exploitable when the application is hosted publicly with a Redis or shelf storage backend. It was published by the maintainer on April 1, 2026, and added to the GitHub Advisory Database on April 3, 2026. The CVSS v3.1 base score is 9.8 (Critical), while the CVSS v4.0 base score is 5.3 (Medium) (GitHub Advisory, D-Tale Advisory).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), though the advisory describes the ultimate impact as remote code execution. The attack vector is network-based, requiring no authentication and no privileges, making it exploitable by any unauthenticated remote attacker against publicly exposed D-Tale instances. The root cause lies in insufficient input sanitization within the Redis or shelf storage layer, where attacker-controlled data can be stored and later deserialized or rendered in a manner that enables server-side code execution. The vulnerability was discovered and reported by researcher QiaoNPC (GitHub Advisory, D-Tale Advisory).
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server hosting D-Tale, resulting in full compromise of confidentiality, integrity, and availability of the affected system (CVSS v3.1 scores all three as High). An attacker could exfiltrate sensitive data processed by D-Tale (e.g., pandas DataFrames containing financial or proprietary datasets), modify server state, install persistent backdoors, or pivot to other internal systems. The impact is limited to deployments using Redis or shelf storage backends that are publicly accessible (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.59% (0.124% per GitHub Advisory, 31st percentile), indicating a relatively low near-term exploitation probability. The vulnerability is detectable by Qualys scanner (detection ID 5010438) and is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (GitHub Advisory, Feedly).
bash, sh, curl, wget, python); unexpected network listeners created by the application process.Users should upgrade D-Tale to version 3.22.0 or later, which contains the fix for this vulnerability. There are no workarounds available for versions prior to 3.22.0 — the only remediation is upgrading. As an additional defensive measure, administrators should avoid exposing D-Tale instances publicly, restrict access via network controls or authentication proxies, and avoid using Redis or shelf storage backends in public-facing deployments until upgraded (GitHub Advisory, D-Tale Advisory).
The advisory was published by D-Tale maintainer aschonfeld on April 1, 2026, and credited researcher QiaoNPC as the finder. No significant broader media coverage, vendor statements beyond the advisory, or notable community commentary has been identified for this vulnerability (D-Tale Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."