CVE-2026-35052: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35052 is a Remote Code Execution (RCE) vulnerability in D-Tale, an open-source Flask/React web client for visualizing pandas DataFrames maintained by Man Group. The flaw affects all D-Tale versions prior to 3.22.0 and is exploitable when the application is hosted publicly with a Redis or shelf storage backend. It was published by the maintainer on April 1, 2026, and added to the GitHub Advisory Database on April 3, 2026. The CVSS v3.1 base score is 9.8 (Critical), while the CVSS v4.0 base score is 5.3 (Medium) (GitHub Advisory, D-Tale Advisory).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting), though the advisory describes the ultimate impact as remote code execution. The attack vector is network-based, requiring no authentication and no privileges, making it exploitable by any unauthenticated remote attacker against publicly exposed D-Tale instances. The root cause lies in insufficient input sanitization within the Redis or shelf storage layer, where attacker-controlled data can be stored and later deserialized or rendered in a manner that enables server-side code execution. The vulnerability was discovered and reported by researcher QiaoNPC (GitHub Advisory, D-Tale Advisory).

Impact

Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server hosting D-Tale, resulting in full compromise of confidentiality, integrity, and availability of the affected system (CVSS v3.1 scores all three as High). An attacker could exfiltrate sensitive data processed by D-Tale (e.g., pandas DataFrames containing financial or proprietary datasets), modify server state, install persistent backdoors, or pivot to other internal systems. The impact is limited to deployments using Redis or shelf storage backends that are publicly accessible (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.59% (0.124% per GitHub Advisory, 31st percentile), indicating a relatively low near-term exploitation probability. The vulnerability is detectable by Qualys scanner (detection ID 5010438) and is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible D-Tale instances (versions < 3.22.0) using search engines like Shodan or Censys, looking for the D-Tale web interface on common ports (typically 40000).
  2. Confirm storage backend: Determine whether the target instance is configured to use Redis or shelf as its storage layer, which is required for exploitation.
  3. Inject malicious payload: Submit crafted input through D-Tale's publicly accessible interface that targets the Redis or shelf storage layer, embedding a payload designed to be deserialized or executed server-side.
  4. Trigger execution: Interact with the application in a way that causes the stored malicious data to be retrieved and processed, resulting in server-side code execution.
  5. Achieve objective: Use the resulting code execution to establish a reverse shell, exfiltrate data, or perform further lateral movement within the network (GitHub Advisory, D-Tale Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the D-Tale server process to external IPs; unusual traffic to/from the Redis port (default 6379) from untrusted sources.
  • Logs: D-Tale or Flask application logs showing unexpected or malformed requests to storage-related endpoints; errors related to deserialization or unexpected data types in Redis/shelf storage.
  • Process: Unusual child processes spawned by the D-Tale/Python process (e.g., bash, sh, curl, wget, python); unexpected network listeners created by the application process.
  • File System: New or modified files in the D-Tale working directory or temp directories; unexpected cron jobs or scheduled tasks created under the service account running D-Tale.

Mitigation and workarounds

Users should upgrade D-Tale to version 3.22.0 or later, which contains the fix for this vulnerability. There are no workarounds available for versions prior to 3.22.0 — the only remediation is upgrading. As an additional defensive measure, administrators should avoid exposing D-Tale instances publicly, restrict access via network controls or authentication proxies, and avoid using Redis or shelf storage backends in public-facing deployments until upgraded (GitHub Advisory, D-Tale Advisory).

Community reactions

The advisory was published by D-Tale maintainer aschonfeld on April 1, 2026, and credited researcher QiaoNPC as the finder. No significant broader media coverage, vendor statements beyond the advisory, or notable community commentary has been identified for this vulnerability (D-Tale Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management