Apache Fory C++ 0.14-1.5 Heap Type Confusion in Deserialization
CVE-2026-71558 Published on August 7, 2026

Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.

Vendor Advisory NVD

Weakness Type

What is a Marshaling, Unmarshaling Vulnerability?

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE-2026-71558 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.


Products Associated with CVE-2026-71558

Want to know whenever a new CVE is published for Apache Fory? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Fory: