Out-of-Bounds Read Vulnerability in Apache Fory Affects Multiple Versions
CVE-2026-64609

9.1CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64609?

The vulnerability involves an out-of-bounds read in Apache Fory due to improper handling of the out-of-band zero-copy deserialization feature. When utilized, this flaw allows the function readAlignedVarUint() to access memory outside the intended buffer limits, leading to potential data leaks. This issue impacts users of versions prior to 1.4.0 and those below 0.11.0, necessitating an immediate upgrade to version 1.4.0 to mitigate the risk.

Affected Version(s)

Apache Fory 0.11.0 < 1.4.0

Apache Fory 0.5.0 < 0.11.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Feng Ning from Innora Security Research
.