Vulnerability Details CVE-2026-64608
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 30.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-64608
-
cpe:2.3:a:apache:fory:0.14.0
-
cpe:2.3:a:apache:fory:0.14.1
-
cpe:2.3:a:apache:fory:0.15.0
-
cpe:2.3:a:apache:fory:0.16.0
-
cpe:2.3:a:apache:fory:0.17.0
-
cpe:2.3:a:apache:fory:1.0.0
-
cpe:2.3:a:apache:fory:1.1.0
-
cpe:2.3:a:apache:fory:1.2.0
-
cpe:2.3:a:apache:fory:1.3.0