CRITICAL🇵🇱 Wersja polska

CVE-2026-50076

CVSS 9.1v3.1pub. 2026-06-04upd. 2026-07-22

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.

🤖 AI Analysis
How it works

The vulnerability (CWE-502) lies in the replace-resolve operation processing path during data deserialization in Apache Fory Java SDK. An attacker can submit crafted serialized data in Fory format, which bypasses type verification and blocked class lists. As a result, deserialization invokes readResolve or readExternal methods present in the application's classpath, which may lead to arbitrary code execution on the server side.

Impact

An attacker can remotely, without authentication, gain full access to data processed by the application (confidentiality) and modify its state or data (integrity). Depending on available classes in the classpath, arbitrary code execution on the server is possible.

Mitigation & patch

Apache Fory must be immediately updated to version 1.1.0 or later, which eliminates the described vulnerability. Details available at https://fory.apache.org/security.

Who is affected

Apache Fory fory-core Java SDK in versions prior to 1.1.0 running on Java/JVM platforms.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Fory

    APP
    Apache
    < 1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-71558CRITICAL9.8PL ✓same product

Apache Fory C++: type confusion w deserializacji umożliwia RCE

CVE-2026-71560CRITICAL9.1PL ✓same product

Apache Fory C++: Out-of-bounds Read podczas deserializacji struktur z polami integer

CVE-2026-64608CRITICAL9.8PL ✓same product

Apache Fory C++: type confusion i out-of-bounds w deserializacji

CVE-2026-64606CRITICAL9.8PL ✓same product

Apache Fury — pominięcie kontroli klas przy deserializacji wyrażeń lambda

CVE-2026-64609CRITICAL9.1PL ✓same product

Apache Fory: out-of-bounds read przy deserializacji zero-copy