Heap Type Confusion Vulnerability in Apache Fory C++
CVE-2026-71558
Currently unrated
What is CVE-2026-71558?
A heap type confusion vulnerability has been identified in Apache Fory C++ due to issues with polymorphic smart-pointer deserialization. This flaw allows a maliciously crafted input payload to bypass type compatibility checks, potentially treating an object of an incorrect type as if it were the declared base type. This can lead to undefined behavior, which may result in the denial of service or arbitrary code execution. It is crucial for users to upgrade to Apache Fory version 1.5.0 or later to mitigate this risk. Applications not leveraging polymorphic smart-pointer deserialization functionalities in Apache Fory C++ remain unaffected.
Affected Version(s)
Apache Fory 0.14.0 < 1.5.0