Improper access control in Apache Fory - CVE-2026-48207
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass deserialization policy restrictions.
The vulnerability exists due to improper access control in ReduceSerializer when deserializing attacker-controlled data during reduce-state restoration and global-name resolution. A remote attacker can supply crafted serialized data to bypass deserialization policy restrictions.
Only applications using PyFory Python-native mode with strict mode disabled and relying on DeserializationPolicy to restrict unsafe classes, functions, or module attributes are vulnerable.