Vulnerability Details CVE-2026-71560
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 43.2%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-71560
-
cpe:2.3:a:apache:fory:0.14.0
-
cpe:2.3:a:apache:fory:0.14.1
-
cpe:2.3:a:apache:fory:0.15.0
-
cpe:2.3:a:apache:fory:0.16.0
-
cpe:2.3:a:apache:fory:0.17.0
-
cpe:2.3:a:apache:fory:1.0.0
-
cpe:2.3:a:apache:fory:1.1.0
-
cpe:2.3:a:apache:fory:1.2.0
-
cpe:2.3:a:apache:fory:1.3.0
-
cpe:2.3:a:apache:fory:1.4.0