Apache Fory (0.13.0-1.3.0) Use-After-Free in Rust Deserialization
CVE-2026-60080 Published on July 21, 2026
Apache Fory: Rust MetaString heap use-after-free
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0.
A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Vulnerability Analysis
CVE-2026-60080 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2026-60080 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2026-60080
Want to know whenever a new CVE is published for Apache Fory? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Fory:- Version 0.13.0, <= 1.3.0 is affected.