Apache Fory C++ OOB Read in Tagged Integer Deserializer (before 1.5.0)
CVE-2026-71560 Published on August 7, 2026
Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2026-71560 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2026-71560
Want to know whenever a new CVE is published for Apache Fory? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Fory:- Version 0.14.0 and below 1.5.0 is affected.