Denial of Service Vulnerability in Apache Fory Affects Remote Applications
CVE-2025-59328

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
15 September 2025

What is CVE-2025-59328?

A vulnerability in Apache Fory allows remote attackers to exploit insecure deserialization of untrusted data, leading to Denial of Service conditions. By submitting a specially crafted data payload, attackers can trigger excessive CPU resource consumption during the deserialization process. This results in the application becoming unresponsive, effectively denying service to legitimate users. It is critical for users of Apache Fory to upgrade to version 0.12.2 or later to ensure the integrity and availability of their applications.

Affected Version(s)

Apache Fory 0.5.0 <= 0.12.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

r00t4dm of meituan security
.
CVE-2025-59328 : Denial of Service Vulnerability in Apache Fory Affects Remote Applications