CVE-2026-35052: Man D-Tale

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.

Affected products

  • Man D-Tale: before 3.22.0 (fixed in 3.22.0)

Published 2026-04-06. Last modified 2026-06-17.