cbcvebase.

Apache Fory vulnerabilities

7 known vulnerabilities affecting apache/fory.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-61622P1CRITICALCVSS 9.8≥ 0.1.0, ≤ 0.10.3≥ 0.12.0, ≤ 0.12.22025-10-01
CVE-2025-61622 [CRITICAL] CWE-502 CVE-2025-61622: Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sources. An attacker can craft a data stream that selects pickle-fallback serializer during des
nvd
CVE-2026-64606P2CRITICALCVSS 9.8≥ 0.5.0, < 1.4.02026-07-21
CVE-2026-64606 [CRITICAL] CWE-502 CVE-2026-64606: Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
nvd
CVE-2026-48207P2CRITICALCVSS 9.8≥ 0.13.0, < 1.0.02026-05-21
CVE-2026-48207 [CRITICAL] CWE-502 CVE-2026-48207: Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docu Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies o
nvd
CVE-2026-50076P2CRITICALCVSS 9.1fixed in 1.1.02026-06-04
CVE-2026-50076 [CRITICAL] CWE-502 CVE-2026-50076: Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to
nvd
CVE-2026-64609P3CRITICALCVSS 9.1≥ 0.5.0, < 1.4.02026-07-21
CVE-2026-64609 [CRITICAL] CWE-125 CVE-2026-64609: Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): fr
nvd
CVE-2026-60080P3HIGHCVSS 7.3≥ 0.13.0, < 1.4.02026-07-21
CVE-2026-60080 [HIGH] CWE-416 CVE-2026-60080: Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
nvd
CVE-2025-59328P3MEDIUMCVSS 6.5≥ 0.5.0, < 0.12.22025-09-15
CVE-2025-59328 [MEDIUM] CWE-502 CVE-2025-59328: A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issu A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payload that, when processed, consumes an excessive amount of CPU resources during the deserialization process. This leads to CPU exhau
nvd
Apache Fory vulnerabilities | cvebase