Apache Fory C++是美国Apache基金会的一款开发框架。 Apache Fory C++ 0.14.0版本至1.4.0之前版本存在安全漏洞,该漏洞源于在兼容模式下反序列化数据时,field-skip路径未正确验证声明的字段类型与实际数据,导致类型混淆和越界内存访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Fory | 0.14.0< 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Fory | 0.14.0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-60080 | Apache Fory: Rust MetaString heap use-after-free | |
| CVE-2026-64606 | Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLam | |
| CVE-2026-64609 | Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deseria |
No comments yet