Type Confusion in Apache Fory - CVE-2026-71558
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to heap type confusion in C++ polymorphic smart-pointer deserialization when parsing a crafted input payload. A remote attacker can send a specially crafted payload to execute arbitrary code or cause a denial of service.
Only applications using C++ polymorphic smart-pointer deserialization are affected.