Use-after-free in Apache Fory - CVE-2026-60080
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to use-after-free in the Rust deserialization logic when parsing a crafted Fory payload. A remote attacker can send a crafted payload to cause a denial of service or disclose sensitive information.
The issue may also result in undefined behavior.