CRITICAL 9.8 NVD

CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input pay

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.

Affected Products

References

Published: 2026-08-07 · Source: NVD · Feed updated: 2026-08-10
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-07 via NVD. Affected: apache/fory.

Risk Timeline

CVE Disclosed2026-08-07 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-61484** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability CRITICAL9.8
CVE-2026-61486** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in ApaCRITICAL9.8
CVE-2026-66909Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessagCRITICAL9.8
CVE-2026-68079In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization codeCRITICAL9.8
CVE-2026-60053Insufficient Session Expiration vulnerability in Apache Answer. This issue affeCRITICAL9.1
CVE-2026-61466In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization sCRITICAL9.1
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.