Deserialization of Untrusted Data in Apache Fory - CVE-2026-50076
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass deserialization security checks and invoke classpath-present deserialization hooks.
The vulnerability exists due to deserialization of untrusted data in the Java replace-resolve path in ReplaceResolverSerializer when processing crafted Fory serialized data. A remote attacker can send crafted serialized data to bypass class registration, TypeChecker, and DisallowedList checks to bypass deserialization security checks and invoke classpath-present deserialization hooks.
The issue affects the Java/JVM implementation.