Apache fory
This hub aggregates every CVE we track for Apache fory, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
8
Critical
2
High
0
In CISA KEV
Severity distribution
CRITICAL8HIGH2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
0
0
0
0
1
1
4
3
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Apache fory.
- CVE-2026-71559Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata7.5
- CVE-2026-71558Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization9.8
- CVE-2026-71560Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path9.1
- CVE-2026-60080Apache Fory: Rust MetaString heap use-after-free7.3
- CVE-2026-64606Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface9.8
- CVE-2026-64609Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization9.1
- CVE-2026-64608Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths9.8
- CVE-2026-50076Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass9.1
- CVE-2026-48207Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement9.8
- CVE-2025-61622Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory9.8
- CVE-2025-59328Apache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data6.5
Product normalization is registry-driven with AI assist and human review. How it works