Known Vulnerabilities for Apache Fory by Apache Software Foundation
Listed below are 9 of the newest known vulnerabilities associated with "Apache Fory" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71560 json | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-71559 json | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial ... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-71558 json | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-64609 json | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-64608 json | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-64606 json | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda de... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-60080 json | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 thr... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-50076 json | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-48207 json | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPol... | Not Provided | 2026-05-21 | 2026-05-21 |