CVE-2026-64608
published 2026-07-21CVE-2026-64608: Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.37%
29.8th percentile
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_fory | >= 0.14.0 < 1.4.0 | 1.4.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Fory 0.14.0/1.3.x C++ implementation out-of-bounds (EUVD-2026-46171)
vuldb·2026-07-21·CVSS 9.8
CVE-2026-64608 [CRITICAL] Apache Fory 0.14.0/1.3.x C++ implementation out-of-bounds (EUVD-2026-46171)
A vulnerability was found in Apache Fory 0.14.0/1.3.x and classified as critical. Affected by this issue is some unknown functionality of the component C++ implementation. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-64608. The attack can be launched remotely. No exploit exists.
GHSA
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation.
ghsa_unreviewed·2026-07-21
CVE-2026-64608 [CRITICAL] CWE-502 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation.
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-21
Published