SB2026082558 - Multiple vulnerabilities in Apache Fory
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2026-64609)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in readAlignedVarUint() when processing out-of-band zero-copy java deserialization data. A remote attacker can supply crafted serialized input to disclose sensitive information.
Only applications that use the opt-in out-of-band zero-copy deserialization feature are affected.
2) Type Confusion (CVE-ID: CVE-2026-64608)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read or write out-of-bounds memory.
The vulnerability exists due to type confusion and out-of-bounds read/write in the C++ compatible-mode field-skip paths when deserializing crafted data with an inconsistent schema. A remote attacker can supply specially crafted serialized input to read or write out-of-bounds memory.
Only the C++ implementation is affected.
3) Improper access control (CVE-ID: CVE-2026-64606)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass class-registration checks during deserialization.
The vulnerability exists due to improper access control in Java lambda deserialization when processing untrusted serialized data. A remote attacker can supply a specially crafted serialized lambda to bypass class-registration checks during deserialization.
Only the lambda capture class is affected.
4) Use-after-free (CVE-ID: CVE-2026-60080)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to use-after-free in the Rust deserialization logic when parsing a crafted Fory payload. A remote attacker can send a crafted payload to cause a denial of service or disclose sensitive information.
The issue may also result in undefined behavior.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=1rtopo9bsm659tfx220n9q34625qwsty
- https://fory.apache.org
- https://lists.apache.org/api/email.lua?id=wnm49y9ynmw7v5skllzy689tp6qds57f
- https://lists.apache.org/api/email.lua?id=z4wpcwfcy6htw3s5tdnwl94wls67njct
- https://lists.apache.org/api/email.lua?id=l0dwncb0mv2sthy5fgo4cmt13l7vkclq