Apache Fory (0.13.0-1.3.0) Use-After-Free in Rust Deserialization
CVE-2026-60080 Published on July 21, 2026
Apache Fory: Rust MetaString heap use-after-free
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0.
A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2026-60080 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2026-60080
Want to know whenever a new CVE is published for Apache Fory? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Fory:- Version 0.13.0, <= 1.3.0 is affected.