Heap Type Confusion Vulnerability in Apache Fory C++
CVE-2026-71558
9.8CRITICAL
What is CVE-2026-71558?
A heap type confusion vulnerability has been identified in Apache Fory C++ due to issues with polymorphic smart-pointer deserialization. This flaw allows a maliciously crafted input payload to bypass type compatibility checks, potentially treating an object of an incorrect type as if it were the declared base type. This can lead to undefined behavior, which may result in the denial of service or arbitrary code execution. It is crucial for users to upgrade to Apache Fory version 1.5.0 or later to mitigate this risk. Applications not leveraging polymorphic smart-pointer deserialization functionalities in Apache Fory C++ remain unaffected.
Affected Version(s)
Apache Fory 0.14.0 < 1.5.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhixi "Jace Sun", independent security researcher