PT-2026-61855 · Apache · Apache Fory

·

CVE-2026-64606

·

Published

2026-07-21

·

Updated

2026-07-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Fory versions prior to 1.4.0
Description An issue exists involving the deserialization of untrusted data, which may allow class-registration checks to be bypassed during Java lambda deserialization. This specifically affects the lambda capture class.
Recommendations Upgrade to version 1.4.0.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64606

Affected Products

Apache Fory