Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not. This issue affects Apache Fory C++: from 0.14.0 before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 30.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-64608
  • Apache » Fory » Version: 0.14.0
    cpe:2.3:a:apache:fory:0.14.0
  • Apache » Fory » Version: 0.14.1
    cpe:2.3:a:apache:fory:0.14.1
  • Apache » Fory » Version: 0.15.0
    cpe:2.3:a:apache:fory:0.15.0
  • Apache » Fory » Version: 0.16.0
    cpe:2.3:a:apache:fory:0.16.0
  • Apache » Fory » Version: 0.17.0
    cpe:2.3:a:apache:fory:0.17.0
  • Apache » Fory » Version: 1.0.0
    cpe:2.3:a:apache:fory:1.0.0
  • Apache » Fory » Version: 1.1.0
    cpe:2.3:a:apache:fory:1.1.0
  • Apache » Fory » Version: 1.2.0
    cpe:2.3:a:apache:fory:1.2.0
  • Apache » Fory » Version: 1.3.0
    cpe:2.3:a:apache:fory:1.3.0


Contact Us

Shodan ® - All rights reserved