Denial of Service Vulnerability in Apache Fory Affects Remote Applications
CVE-2025-59328
6.5MEDIUM
What is CVE-2025-59328?
A vulnerability in Apache Fory allows remote attackers to exploit insecure deserialization of untrusted data, leading to Denial of Service conditions. By submitting a specially crafted data payload, attackers can trigger excessive CPU resource consumption during the deserialization process. This results in the application becoming unresponsive, effectively denying service to legitimate users. It is critical for users of Apache Fory to upgrade to version 0.12.2 or later to ensure the integrity and availability of their applications.
Affected Version(s)
Apache Fory 0.5.0 <= 0.12.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
r00t4dm of meituan security