Severity: moderate 

Affected versions:

- Apache Fory 0.16.0 before 1.5.0

Description:

Deserialization of Untrusted Data vulnerability in the Go implementation of 
Apache Fory allows an attacker to cause a denial of service by supplying 
crafted data containing malformed type metadata, which triggers an uncaught 
panic.

This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other 
language implementations are not affected.

Users are recommended to upgrade to version 1.5.0, which fixes the issue.

Credit:

Zhixi "Jace Sun", independent security researcher (reporter)

References:

https://fory.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-71559

Reply via email to