Severity: important 

Affected versions:

- Apache Fory (org.apache.fory:fory-core) before 1.1.0

Description:

Deserialization of Untrusted Data in the Java replace-resolve path in Apache 
Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote 
attacker to bypass class registration, TypeChecker, and DisallowedList checks 
and invoke classpath-present readResolve/readExternal hooks via crafted Fory 
serialized data.

Users are recommended to upgrade to version 1.1.0 or later, which fixes this 
issue.

Credit:

Venkatraman Kumar (r3dw0lfsec), Securin (reporter)

References:

https://fory.apache.org/security
https://fory.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-50076

Reply via email to