Denial of Service Vulnerability in Apache Fory Affects Remote Applications
CVE-2025-59328
What is CVE-2025-59328?
A vulnerability in Apache Fory allows remote attackers to exploit insecure deserialization of untrusted data, leading to Denial of Service conditions. By submitting a specially crafted data payload, attackers can trigger excessive CPU resource consumption during the deserialization process. This results in the application becoming unresponsive, effectively denying service to legitimate users. It is critical for users of Apache Fory to upgrade to version 0.12.2 or later to ensure the integrity and availability of their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Fory 0.5.0 <= 0.12.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved