CVE-2026-35052: Man D-Tale
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.
Affected products
- Man D-Tale: before 3.22.0 (fixed in 3.22.0)
Published 2026-04-06. Last modified 2026-06-17.