CVE-2026-64609
published 2026-07-21CVE-2026-64609: Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of…
PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.34%
27.0th percentile
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected.
This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | fory | >= 0.5.0 < 1.4.0 | 1.4.0 |
| apache_software_foundation | apache_fory | >= 0.11.0 < 1.4.0 | 1.4.0 |
| apache_software_foundation | apache_fory | >= 0.5.0 < 0.11.0 | 0.11.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Out-of-bounds read via sun.misc.Unsafe in Apache Fory.
ghsa_unreviewed·2026-07-21
CVE-2026-64609 [CRITICAL] CWE-125 Out-of-bounds read via sun.misc.Unsafe in Apache Fory.
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected.
This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
VulDB
Apache Fory up to 1.3.x sun.misc.Unsafe readAlignedVarUint out-of-bounds (EUVD-2026-46172)
vuldb·2026-07-21·CVSS 9.1
CVE-2026-64609 [CRITICAL] Apache Fory up to 1.3.x sun.misc.Unsafe readAlignedVarUint out-of-bounds (EUVD-2026-46172)
A vulnerability has been found in Apache Fory up to 1.3.x and classified as critical. Affected by this vulnerability is the function readAlignedVarUint of the component sun.misc.Unsafe. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-64609. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-21
Published