Every CVE whose affected-product data names Apache Fory, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2026-64606 — CVSS 9.8 (critical): Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization…
CVE-2026-64608 — CVSS 9.8 (critical): Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the…
CVE-2026-48207 — CVSS 9.8 (critical): Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation…
CVE-2025-61622 — CVSS 9.8 (critical): Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through…
CVE-2026-71558 — CVSS 9.8 (critical): Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0…
CVE-2026-71560 — CVSS 9.1 (critical): Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0…
CVE-2026-50076 — CVSS 9.1 (critical): Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms…
CVE-2026-64609 — CVSS 9.1 (critical): Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read…
CVE-2026-71559 — CVSS 7.5 (high): Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by…
CVE-2026-60080 — CVSS 7.3 (high): Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A…
CVE-2025-59328 — CVSS 6.5 (medium): A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure…