PT-2026-68891 · Apache · Apache Fory

CVE-2026-71560

·

Published

2026-08-07

·

Updated

2026-08-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Fory C++ versions 0.14.0 through 1.4.x
Description An out-of-bounds read issue exists during the deserialization of structs containing tagged integer fields. A crafted input payload can trigger an out-of-bounds heap read within the tagged integer fast-path deserializer, which may lead to denial of service or information disclosure.
Recommendations Upgrade to version 1.5.0. Restrict the use of tagged integer fields during deserialization as a temporary mitigation.

Fix

DoS

Out of bounds Read

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71560

Affected Products

Apache Fory