Severity: important 

Affected versions:

- Apache Fory (fory-core) 0.13.0 through 1.3.0

Description:

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. 
This issue affects Apache Fory from 0.13.0 through 1.3.0.

 A crafted Fory payload could cause undefined behavior, process crash, or 
potential memory disclosure.

Users are recommended to upgrade to version 1.4.0, which fixes the issue.

Credit:

Nguyen Van Hiep (@hypnguyen1209) from MBBank (reporter)

References:

https://fory.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-60080

Reply via email to