VYPR
High severity7.5NVD Advisory· Published Aug 7, 2026· Updated Aug 8, 2026

CVE-2026-71559

CVE-2026-71559

Description

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.

This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected.

Users are recommended to upgrade to version 1.5.0, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Apache/Fory2 versions
    cpe:2.3:a:apache:fory:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:fory:*:*:*:*:*:*:*:*range: >=0.16.0,<1.5.0
    • (no CPE)range: 0.16.0 <= v < 1.5.0

Patches

Vulnerability mechanics

References

2

News mentions

1