PT-2026-61854 · Apache · Apache Fory

·

CVE-2026-64609

·

Published

2026-07-21

·

Updated

2026-07-27

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Fory versions 0.5.0 through 1.3.x
Description An out-of-bounds read occurs via sun.misc.Unsafe when out-of-band zero-copy deserialization is utilized. In this scenario, the readAlignedVarUint() function can read data beyond the boundaries of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature, meaning applications that do not enable this specific functionality are not impacted.
Recommendations Upgrade to version 1.4.0. As a temporary mitigation, avoid using the out-of-band zero-copy deserialization feature.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64609

Affected Products

Apache Fory