All 4 CVE vulnerabilities found in Apache Fory, with AI-generated Chinese analysis, references, and POCs.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50076 | Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass CWE-502 | - | - | 2026-06-04 |
| CVE-2026-48207 | Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement CWE-502 | - | - | 2026-05-21 |
| CVE-2025-61622 | Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory CWE-502 | 9.8AI | CriticalAI | 2025-10-01 |
| CVE-2025-59328 | Apache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large Data CWE-502 | 7.5AI | HighAI | 2025-09-15 |
All 4 known CVE vulnerabilities affecting Apache Fory with full Chinese analysis, references, and POCs where available.