CVE-2026-48207
Description
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes.
This issue affects Apache Fory: from before 1.0.0.
Mitigation: Users of Apache Fory are recommended to upgrade to version 1.0.0 or later, which enforces DeserializationPolicy validation for the affected ReduceSerializer paths and thus fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyforyPyPI | >= 0.13.0, < 1.0.0 | 1.0.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/05/21/10nvdMailing ListThird Party AdvisoryWEB
- fory.apache.org/security/nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-m5gw-83w2-7749ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48207ghsaADVISORY
News mentions
0No linked articles in our index yet.