CRITICALVulnerability
CVE-2026-64608
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not. This issue affects Apache Fory C++: from 0.14.0 before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Properties
- severity
- CRITICAL
- score
- 9.8
- cve_id
- CVE-2026-64608
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-07-21T10:16:24.923
- last_modified
- 2026-08-11T18:58:04.640
Related Entities (5)
HAS_WEAKNESS (3)
→[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')
→[Weakness]Deserialization of Untrusted Data
→[Weakness]Out-of-bounds Write
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph