Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 43.2%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-71560
  • Apache » Fory » Version: 0.14.0
    cpe:2.3:a:apache:fory:0.14.0
  • Apache » Fory » Version: 0.14.1
    cpe:2.3:a:apache:fory:0.14.1
  • Apache » Fory » Version: 0.15.0
    cpe:2.3:a:apache:fory:0.15.0
  • Apache » Fory » Version: 0.16.0
    cpe:2.3:a:apache:fory:0.16.0
  • Apache » Fory » Version: 0.17.0
    cpe:2.3:a:apache:fory:0.17.0
  • Apache » Fory » Version: 1.0.0
    cpe:2.3:a:apache:fory:1.0.0
  • Apache » Fory » Version: 1.1.0
    cpe:2.3:a:apache:fory:1.1.0
  • Apache » Fory » Version: 1.2.0
    cpe:2.3:a:apache:fory:1.2.0
  • Apache » Fory » Version: 1.3.0
    cpe:2.3:a:apache:fory:1.3.0
  • Apache » Fory » Version: 1.4.0
    cpe:2.3:a:apache:fory:1.4.0


Contact Us

Shodan ® - All rights reserved