Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-71558: Apache Fory: Malicious Data Can Crash or Hijack Server
CVE-2026-71558 · published 28 days ago
Summary
Apache Fory's C++ deserialization feature is affected by a security flaw. If exploited, this could cause your server to crash or allow attackers to take control of it. To fix this, upgrade to the latest version of Apache Fory, version 1.5.0, if you use this feature.
What to do
- Update apache software foundation apache fory to version 1.5.0 or later.
- Update apache fory to version 1.5.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache fory | < 1.5.0 |
| apache | fory |
>= 0.14.0, < 1.5.0 cpe:2.3:a:apache:fory:*:*:*:*:*:*:*:* |
Original advisory text
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility ch...
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
CWE-843Type Confusion
Timeline
Published7 Aug 2026
Updated3 Sep 2026
First seen7 Aug 2026
Monitor software like this
Free during beta