Out-of-bounds read in Apache Fory - CVE-2026-64609
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in readAlignedVarUint() when processing out-of-band zero-copy java deserialization data. A remote attacker can supply crafted serialized input to disclose sensitive information.
Only applications that use the opt-in out-of-band zero-copy deserialization feature are affected.