Unrated severityNVD Advisory· Published Aug 7, 2026· Updated Aug 7, 2026
CVE-2026-71559
CVE-2026-71559
Description
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.