Type Confusion in Apache Fory - CVE-2026-64608
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to read or write out-of-bounds memory.
The vulnerability exists due to type confusion and out-of-bounds read/write in the C++ compatible-mode field-skip paths when deserializing crafted data with an inconsistent schema. A remote attacker can supply specially crafted serialized input to read or write out-of-bounds memory.
Only the C++ implementation is affected.