CVE-2026-71559
- EPSS 0.18%
- Veröffentlicht 07.08.2026 08:56:09
- Zuletzt bearbeitet 08.08.2026 01:02:26
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affect...
CVE-2026-71558
- EPSS 0.21%
- Veröffentlicht 07.08.2026 08:54:56
- Zuletzt bearbeitet 08.08.2026 00:52:49
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization...
CVE-2026-71560
- EPSS 0.18%
- Veröffentlicht 07.08.2026 08:53:36
- Zuletzt bearbeitet 08.08.2026 00:46:13
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-boun...
CVE-2026-60080
- EPSS 0.42%
- Veröffentlicht 21.07.2026 10:54:19
- Zuletzt bearbeitet 27.07.2026 13:47:47
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users ar...
CVE-2026-64606
- EPSS 0.63%
- Veröffentlicht 21.07.2026 10:43:51
- Zuletzt bearbeitet 27.07.2026 13:47:41
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommen...
CVE-2026-64609
- EPSS 0.48%
- Veröffentlicht 21.07.2026 09:34:57
- Zuletzt bearbeitet 27.07.2026 13:47:44
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applicati...
CVE-2026-64608
- EPSS 0.48%
- Veröffentlicht 21.07.2026 09:34:12
- Zuletzt bearbeitet 11.08.2026 18:58:04
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inco...
CVE-2026-50076
- EPSS 0.52%
- Veröffentlicht 04.06.2026 16:09:03
- Zuletzt bearbeitet 22.07.2026 20:10:00
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath...
CVE-2026-48207
- EPSS 0.57%
- Veröffentlicht 21.05.2026 17:16:21
- Zuletzt bearbeitet 23.07.2026 16:10:00
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deseriali...
CVE-2025-61622
- EPSS 41.26%
- Veröffentlicht 01.10.2025 10:15:34
- Zuletzt bearbeitet 03.12.2025 21:52:30
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untru...