Heap Type Confusion in Apache Fory C++ Implementation
CVE-2026-64608
9.8CRITICAL
What is CVE-2026-64608?
A vulnerability exists in the Apache Fory C++ implementation due to improper validation of field types during data deserialization in compatible mode. This flaw allows input with inconsistent schema to lead to type confusion and out-of-bounds memory access. Only the C++ version is susceptible; other language implementations remain unaffected. Users are strongly advised to upgrade to version 1.4.0 to mitigate this security issue.
Affected Version(s)
Apache Fory 0.14.0 < 1.4.0