VendorsApacheforyany version
Vulnerabilities

Apache Software Foundation Fory any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2025-61622
Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory
Published 2025-10-01 · Analyzed
9.8EPSS 0.435
CVE-2026-71558
Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Published 2026-08-07 · Analyzed
9.8EPSS 0.010
CVE-2026-48207
Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement
Published 2026-05-21 · Analyzed
9.8EPSS 0.008
CVE-2026-64608
Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Published 2026-07-21 · Analyzed
9.8EPSS 0.008
CVE-2026-64606
Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Published 2026-07-21 · Analyzed
9.8EPSS 0.008
CVE-2026-64609
Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Published 2026-07-21 · Analyzed
9.1EPSS 0.008
CVE-2026-71560
Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Published 2026-08-07 · Analyzed
9.1EPSS 0.008
CVE-2026-50076
Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Published 2026-06-04 · Analyzed
9.1EPSS 0.007
CVE-2026-71559
Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Published 2026-08-07 · Analyzed
7.5EPSS 0.008
CVE-2026-60080
Apache Fory: Rust MetaString heap use-after-free
Published 2026-07-21 · Analyzed
7.3EPSS 0.007
CVE-2025-59328
Apache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data
Published 2025-09-15 · Modified
6.5EPSS 0.006