VYPR

fory-core

by Apache

CVEs (1)

  • CVE-2026-50076CriJun 4, 2026
    risk 0.52cvss 9.1epss

    Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present…