Apache
Apache Fory: vulnerabilidades y CVE
Apache Fory tiene 11 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses9
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71560 | Crítica (9.1) | 0.77% | — | 7 ago 2026 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input… |
| CVE-2026-71559 | Alta (7.5) | 0.80% | — | 7 ago 2026 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an… |
| CVE-2026-71558 | Crítica (9.8) | 0.99% | — | 7 ago 2026 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic… |
| CVE-2026-60080 | Alta (7.3) | 0.68% | — | 21 jul 2026 | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential… |
| CVE-2026-64606 | Crítica (9.8) | 0.78% | — | 21 jul 2026 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from… |
| CVE-2026-64609 | Crítica (9.1) | 0.78% | — | 21 jul 2026 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization… |
| CVE-2026-64608 | Crítica (9.8) | 0.81% | — | 21 jul 2026 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the… |
| CVE-2026-50076 | Crítica (9.1) | 0.74% | — | 4 jun 2026 | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and… |
| CVE-2026-48207 | Crítica (9.8) | 0.82% | — | 21 may 2026 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An… |
| CVE-2025-61622 | Crítica (9.8) | 44% | — | 1 oct 2025 | Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads… |
| CVE-2025-59328 | Media (6.5) | 0.64% | — | 15 sept 2025 | A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.