Heap Type Confusion in Apache Fory C++ Implementation
CVE-2026-64608

9.8CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64608?

A vulnerability exists in the Apache Fory C++ implementation due to improper validation of field types during data deserialization in compatible mode. This flaw allows input with inconsistent schema to lead to type confusion and out-of-bounds memory access. Only the C++ version is susceptible; other language implementations remain unaffected. Users are strongly advised to upgrade to version 1.4.0 to mitigate this security issue.

Affected Version(s)

Apache Fory 0.14.0 < 1.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Van Hiep (@hypnguyen1209) from MBBank
.