Out-of-Bounds Read Vulnerability in Apache Fory Affects Multiple Versions
CVE-2026-64609
9.1CRITICAL
What is CVE-2026-64609?
The vulnerability involves an out-of-bounds read in Apache Fory due to improper handling of the out-of-band zero-copy deserialization feature. When utilized, this flaw allows the function readAlignedVarUint() to access memory outside the intended buffer limits, leading to potential data leaks. This issue impacts users of versions prior to 1.4.0 and those below 0.11.0, necessitating an immediate upgrade to version 1.4.0 to mitigate the risk.
Affected Version(s)
Apache Fory 0.11.0 < 1.4.0
Apache Fory 0.5.0 < 0.11.0