Apache Fory C++ OOB Read in Tagged Integer Deserializer (before 1.5.0)
CVE-2026-71560 Published on August 7, 2026

Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.

Vendor Advisory NVD

Weakness Type

What is a Marshaling, Unmarshaling Vulnerability?

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

CVE-2026-71560 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.


Products Associated with CVE-2026-71560

Want to know whenever a new CVE is published for Apache Fory? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Fory: